Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Liaoning Vtime Technology 188Jianzhan SQL注入漏洞
Vulnerability Description
Liaoning Vtime Technology 188Jianzhan(妖巴巴建站系统)是中国辽宁微时光科技(Liaoning Vtime Technology)公司的一个开源建站系统。 188Jianzhan v2.1.0存在SQL注入漏洞,该漏洞源于软件中login.php中的username参数缺少有效的限制与转义。这允许攻击者可利用该漏洞执行任意代码,并通过login.php的username参数获得升级的权限。
CVSS Information
N/A
Vulnerability Type
N/A