Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gxlcms QY 安全漏洞
Vulnerability Description
Gxlcms QY是一套企业网站创建系统。 Gxlcms QY 1.0.0713版本中的\Lib\Lib\Action\Admin\DataAction.class.php文件的‘upsql’函数存在安全漏洞。远程攻击者可借助‘sql’参数利用该漏洞执行任意SQL语句,然后执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A