Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
polterguy Phosphorus Five CSV Import NonQuery.cs csv.Read sql injection
Vulnerability Description
A vulnerability has been found in polterguy Phosphorus Five up to 8.2 and classified as critical. This vulnerability affects the function csv.Read of the file plugins/extras/p5.mysql/NonQuery.cs of the component CSV Import. The manipulation leads to sql injection. Upgrading to version 8.3 is able to address this issue. The patch is identified as c179a3d0703db55cfe0cb939b89593f2e7a87246. It is recommended to upgrade the affected component. VDB-217606 is the identifier assigned to this vulnerability.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Phosphorus Five SQL注入漏洞
Vulnerability Description
Phosphorus Five是Aista开源的一个基于 .Net 的 RAD Web 应用程序开发框架。用于创建丰富且安全的 Ajax Web 应用程序。 Phosphorus Five 8.3之前版本存在SQL注入漏洞,该漏洞源于组件CSV Import中plugins/extras/p5.mysql/NonQuery.cs文件的csv.Read函数存在问题,会导致sql注入。
CVSS Information
N/A
Vulnerability Type
N/A