Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
b2evolution SQL注入漏洞
Vulnerability Description
b2evolution是一套基于PHP和MySQL的社区内容管理系统。 b2evolution v7.2.2-stable 版本存在SQL注入漏洞,该漏洞允许远程攻击者可利用该漏洞在“Collections”选项卡下创建新的过滤器时,通过将SQL命令注入“cf name”参数来获取敏感的数据库信息。
CVSS Information
N/A
Vulnerability Type
N/A