漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SQL Injection in MegaBIP
Vulnerability Description
SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages. This issue affects MegaBIP software versions through 5.13.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:I/V:D/RE:M/U:Amber
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
MegaBIP 安全漏洞
Vulnerability Description
MegaBIP是一个用于创建BIP网站的软件。 MegaBIP 5.13及之前版本存在安全漏洞,该漏洞源于参数中存在SQL注入漏洞,允许未经授权的攻击者泄露数据库内容并获取管理员令牌来修改页面内容。
CVSS Information
N/A
Vulnerability Type
N/A