Xoops WebChat Module Remote SQL...

- AV AC AU C I A
发布: 2002-11-12
修订: 2025-04-13

A vulnerability exists in the WebChat module included with Xoops. The vulnerability is due to insufficient sanitization of variables used to construct SQL queries in the 'index.php' script. It is possible to modify the logic of SQL queries through malformed query strings in requests for the vulnerable script. By injecting SQL code into variables, it may be possible for an attacker to corrupt database information.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息