Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Spotweb SQL注入漏洞
Vulnerability Description
Spotweb是Spotweb团队的一款基于Php的遵循Spotnet协议的Soptnet客户端。 Spotweb 1.4.9 存在SQL注入漏洞,该漏洞源于notAllowedCommands保护机制不充分。
CVSS Information
N/A
Vulnerability Type
N/A