Mini SQL w3-msql Vulnerability...

- AV AC AU C I A
发布: 1999-08-18
修订: 2025-04-13

Under certain versions of Mini SQL, the w3-msql CGI script allows users to view directories which are set for private access via .htaccess files. W3-mSQL converts any form data passed to a script into global Lite variables and these variables can then be accessed by your script code. When an HTML form is defined a field name is given to each element of the form. When the data is passed to W3-mSQL the field names are used as the variable names for the global variables. Once a set of variables has been created for each form element, the values being passed to the script are assigned to the variables. This is done automatically during start-up of the W3-mSQL program.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息