Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. Sending an improper variable type of Array allows a bypass of core SQL Injection sanitization. Authenticated users are able to inject malicious SQL queries. This vulnerability leads to full database leak including ckeys that can be used in the authentication process without knowing the username and cleartext password. This can occur via the ajax/actions.php group_id field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Observium Professional Enterprise Community SQL注入漏洞
Vulnerability Description
Observium是英国observium的一个免费的服务器监控平台。该平台由PHP编写的基于自动发现 SNMP 的网络监控平台,支持非常广泛的网络硬件和操作系统,包括 Cisco、Windows、Linux、HP、NetApp 等等。 Observium Professional Enterprise 和Community 20.8.10631版本存在SQL注入漏洞,该漏洞源于无需知道用户名和明文密码,攻击者可利用该漏洞通过ajax / actions.php group_id字段触发。
CVSS Information
N/A
Vulnerability Type
N/A