XATABoost CMS是XATABoost公司的一个提供网站内容发布与管理功能的内容管理系统。 XATABoost CMS 1.0.0版本存在SQL注入漏洞,该漏洞源于基于联合的SQL注入,可能导致未经身份验证的攻击者通过id参数注入SQL代码操纵数据库查询,向news.php发送带有恶意id值的GET请求以提取敏感数据库信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xataboost | XATABoost CMS | 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xataboost | XATABoost CMS | 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet