Joel Palmius Mod_Survey Data...

- AV AC AU C I A
发布: 2003-03-23
修订: 2025-04-13

Mod_Survey does not sufficiently sanitize data supplied via ENV tags. It has been reported by the vendor that this may allow for injection of malicious data into the data repository. Exploitation may allow for manipulation of environment variables or the possibility of executing database commands through injection of SQL syntax. Other attacks which may also be possible. This is only an issue with surveys that use ENV tags.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息