
CVE-2024-34310
CVE-2024-34310
[Vorgeschlagene Beschreibung] Jin Fang Times Content Management System v3.2.3 wurde entdeckt, dass eine SQL-Injection-Schwachstelle über den id-Parameter enthält.
[Schwachstellentyp] SQL-Injection
[Produktanbieter] https://www.bjjfsd.com/
[Betroffene Produktcodebasis] Jin Fang times content management system - 3.2.3
[Betroffene Komponente] public function data_show($id = 0) {
if (empty($id)) { $this->redirect('index'); }$info = M('News')->find($id);
[Angriffstyp] Remote
[Auswirkung Codeausführung] true
[Auswirkung Informationsoffenlegung] true
[Angriffsvektoren] m=Wap&c=Index&a=data_show&id[where]=1%20or%20updatexml(0,user(),0)
[Entdecker] yishan
[Referenz] http://jin.com https://www.bjjfsd.com/
Verwenden Sie CVE-2024-34310.