CakePHP 是一个用于 PHP 的 rapid development(快速开发)框架。在 4.5.12、4.6.5、5.1.9、5.2.14 和 5.3.7 之前版本中, 文件中的 、 、 和 函数接受用户可控的 、 或 参数,并将这些值作为未转义的结构化片段直接拼接到生成的 SQL 语句中。如果应用程序将这些参数传入不受信任的用户输入,则可能导致 SQL 注入漏洞,其影响范围取决于数据库连接所具有的权限,可能危及数据的机密性、完整性和可用性。该问题已在 4.5.12、4.6.5、5.1.9、5.2.14 和
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet