在 QCMS(Quick CMS)6.0.6 及更早版本中检测到一项安全漏洞。该问题影响“内容详情页”组件中 库的 函数。对 参数的不当操作可导致 SQL 注入攻击。攻击者可远程实施此攻击。该漏洞利用方法已公开披露,且可能已被利用。 由于路由器直接使用原始的 而未进行 URL 解码,因此路由解析前 不会被解码,攻击负载(payload)中必须包含字面空格。 厂商的支持团队在披露该漏洞时已提前联系,但遗憾的是,他们仅以侮辱性言语回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | QCMS | 6.0.0 |
cpe:2.3:a:qcms:qcms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94103 | 4.7 MEDIUM | RooCMS Frontend Rendering site_pagePHP.php eval code injection |
| CVE-2026-94102 | 4.3 MEDIUM | WuzhiCMS Login index.php redirect |
No comments yet