Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to sh -c without sanitization, allowing attackers to execute arbitrary commands.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
sqls 安全漏洞
Vulnerability Description
sqls是sqls-server开源的一个用Go编写的SQL语言服务器。 sqls 0.2.28版本存在安全漏洞,该漏洞源于openEditor函数未清理EDITOR环境变量和配置文件路径,可能导致命令注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A