Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Data Center Audit 2.6.2 SQL Injection via username Parameter
Vulnerability Description
Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database names, and version details.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Data Center Audit SQL注入漏洞
Vulnerability Description
Data Center Audit是Ben Patridge个人开发者的一个数据审计软件。 Data Center Audit 2.6.2版本存在SQL注入漏洞,该漏洞源于dca_login.php中的username参数存在SQL注入问题,可能导致未经验证的攻击者执行任意SQL查询。
CVSS Information
N/A
Vulnerability Type
N/A