Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-1747: sql/ibos sql injection.md · wkstestete/cve - Gitee.com

A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-224635.

CVE
#sql#vulnerability#git

该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。

项目仓库所选许可证以仓库主分支所使用许可证为准

克隆/下载

下载ZIP

登录提示

该操作需登录 Gitee 帐号,请先登录后再操作。

立即登录

没有帐号,去注册

cve

/

sql

/

ibos sql injection.md

ibos sql injection.md 352 Bytes

SQL injection exists in versions of ibos oa below 4.5.5

routing:r=email/api/mark&op=delFromSend

1.Log in the background to find the email has been sent, delete a mail and grab the packet

2.POC

Get the database version by error injection

误判申诉

此处可能存在不合适展示的内容,页面不予展示。您可通过相关编辑功能自查并修改。

如您确认内容无涉及 不当用语 / 纯广告导流 / 暴力 / 低俗色情 / 侵权 / 盗版 / 虚假 / 无价值内容或违法国家有关法律法规的内容,可点击提交进行申诉,我们将尽快为您处理。

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907