
CVE-2024-34310
CVE-2024-34310
[建议描述] 发现 Jin Fang Times 内容管理系统 v3.2.3 存在 SQL 注入漏洞,通过 id 参数触发。
[漏洞类型] SQL 注入
[厂商产品] https://www.bjjfsd.com/
[受影响产品代码库] Jin Fang times content management system - 3.2.3
[受影响组件] public function data_show($id = 0) {
if (empty($id)) { $this->redirect('index'); }$info = M('News')->find($id);
[攻击类型] 远程
[影响代码执行] true
[影响信息泄露] true
[攻击向量] m=Wap&c=Index&a=data_show&id[where]=1%20or%20updatexml(0,user(),0)
[发现者] yishan
使用 CVE-2024-34310.