| ଶୀର୍ଷକ | SQL injection vulnerability exists in DedeBIZ v6.2.10 |
|---|
| ବର୍ଣ୍ଣନା | [Suggested description]
DedeBIZ v6.2.10 was discovered to contain SQL injection vulnerability in /admin/sys_sql_query.php.
[Vulnerability Type]
SQL INJECTION
[Vendor of Product]
https://github.com/DedeBIZ/DedeV6
https://www.dedebiz.com/
[Affected Product Code Base]
DedeBIZ 6.2.10
[Affected Component]
File:admin/sys_sql_query.php
Parameter:sqlquery
---
Parameter: sqlquery (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 time-based blind - Parameter replace (substraction)
Payload: dopost=query&_csrf_token=ba4a9cf92c1a646452a0bf31177d42f0&querytype=0&sqlquery=(SELECT 7474 FROM (SELECT(SLEEP(5)))OrpC)
---
Detail:https://github.com/TXPH/CVE/blob/main/sqli-report.pdf
[Attack Type]
Remote
[Vulnerability demonstration]
|
|---|
| ଉତ୍ସ | ⚠️ https://github.com/TXPH/CVE/blob/main/sqli-report.pdf |
|---|
| ଉପଭୋକ୍ତା | TXPH (UID 50296) |
|---|
| ଦାଖଲ | 07/14/2023 08:02 AM (3 ବର୍ଷ ବର୍ଷ ago) |
|---|
| ମଧ୍ୟମ ଧରଣର | 07/22/2023 08:13 AM (8 days later) |
|---|
| ସ୍ଥିତି | ଗ୍ରହଣ କରାଯାଇଛି |
|---|
| VulDB ଏଣ୍ଟ୍ରି | 235190 [DedeBIZ 6.2.10 /admin/sys_sql_query.php sqlquery SQL ଇଞ୍ଜେକ୍ସନ] |
|---|
| ପଏଣ୍ଟ | 20 |
|---|