Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php
Vulnerability Description
xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
xbtitFM SQL注入漏洞
Vulnerability Description
xbtitFM是xbtitFM个人开发者的一个BitTorrent追踪器软件。 xbtitFM 4.1.18版本存在SQL注入漏洞,该漏洞源于msgid参数存在SQL注入,可能导致提取数据库凭据。
CVSS Information
N/A
Vulnerability Type
N/A