Archery是一套开源的漏洞评估和管理工具。 Archery 存在SQL注入漏洞,该漏洞源于包含多个 SQL 注入漏洞,可能允许攻击者查询连接的数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-30558 | 6.5 MEDIUM | Multiple SQL injections in sql/data_dictionary.py table_list method in Archery - GHSL-2022 |
| CVE-2023-30552 | 6.5 MEDIUM | SQL injection in sql/instance.py endpoint in Archery - GHSL-2022-101 |
| CVE-2023-30553 | 6.5 MEDIUM | Multiple SQL injections in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-102 |
| CVE-2023-30554 | 6.5 MEDIUM | SQL injection in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-103 |
| CVE-2023-30555 | 6.5 MEDIUM | SQL injection in sql_optimize.py explain method in Archery - GHSL-2022-108 |
| CVE-2023-30556 | 6.5 MEDIUM | SQL injection in sql_optimize.py optimize_sqltuningadvisor method in Archery - GHSL-2022-1 |
| CVE-2023-30557 | 6.5 MEDIUM | SQL injection in data_dictionary.py table_info method in Archery - GHSL-2022-106 |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.