Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL injection in ext-pgsql via E'...' backslash breakout
Vulnerability Description
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
php.net The PHP Interpreter SQL注入漏洞
Vulnerability Description
php group php是php group团队开源的一种服务器端脚本语言。 php.net The PHP Interpreter 8.2.33之前版本、8.3.33之前版本、8.4.24之前版本和8.5.9之前版本存在SQL注入漏洞,该漏洞源于攻击者提供的参数中反斜杠转义不当,可能导致SQL注入。
CVSS Information
N/A
Vulnerability Type
N/A