Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPOK SQL注入漏洞
Vulnerability Description
PHPOK是一套支持扩展的企业建站系统。 PhpOK 5.4.137版本存在SQL注入漏洞,该漏洞源于基于数据库的应用缺少对外部输入SQL语句的验证。攻击者可可以通过SQL注入附件数据,然后通过api.php调用附件替换函数,将PHP文件写入目标路径。
CVSS Information
N/A
Vulnerability Type
N/A