Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vinades NukeViet SQL注入漏洞
Vulnerability Description
Vinades NukeViet是越南VINADES(Vinades)公司的一套开源的内容管理系统(CMS)。 NukeViet CMS 中存在SQL注入漏洞,该漏洞源于产品商铺模块 detail.php 页面的 listid 参数和 和 search_result.php 页面的group_price、 groupid参数未能过滤特殊字符。攻击者可通过该漏洞执行非法SQL语句。以下产品及版本受到影响:NukeViet CMS 4.0.29 版本和 4.3版本。
CVSS Information
N/A
Vulnerability Type
N/A