Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Synnefo Internet Management Software 安全漏洞
Vulnerability Description
Synnefo Internet Management Software(SynnefoIMS)是Synnefo公司的一个互联网管理软件。 Synnefo Internet Management Software 2023及之前版本版本存在安全漏洞,该漏洞源于存在SQL注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A