Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ServiceTonic Helpdesk Software SQL注入漏洞
Vulnerability Description
ServiceTonic Helpdesk Software是西班牙ServiceTonic公司的一款多功能服务管理软件。 ServiceTonic Helpdesk 9.0.35937之前版本存在安全漏洞,该漏洞源于登录表单中盲目的SQL注入,攻击者可利用该漏洞通过专门制作的兼容hql的基于时间的SQL查询来窃取信息。
CVSS Information
N/A
Vulnerability Type
N/A