VBulletin SQL Query Manipulation...

- AV AC AU C I A
发布: 2002-03-10
修订: 2025-04-13

vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems. Affected versions of vBulletin do not sufficiently sanitize user-supplied input before it is used to construct a SQL query, making it prone to SQL query injection. This issue only occurs when vBulletin has been configured to allow guest postings.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息