Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bo-blog Wind SQL注入漏洞
Vulnerability Description
Bo-blog Wind是一套轻量级个人博客系统。 Bo-blog Wind 1.6.0-r及之前版本中的admin.php/comments/batchdel/存在SQL注入漏洞,该漏洞源于程序错误地处理了‘comID’参数。远程攻击者可借助‘comID’参数利用该漏洞查看、添加、修改或删除后端数据库中的信息。
CVSS Information
N/A
Vulnerability Type
N/A