漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution
Vulnerability Description
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Nextcloud Tables SQL注入漏洞
Vulnerability Description
Nextcloud Tables是Nextcloud开源的一个表格应用程序。 Nextcloud Tables 0.7.0版本至0.7.7之前版本、0.8.0版本至0.8.10之前版本、0.9.0版本至0.9.8之前版本和1.0.0版本至1.0.4之前版本存在SQL注入漏洞,该漏洞源于存储型注入,可能导致已认证攻击者执行最长20字节的任意SQL查询。
CVSS Information
N/A
Vulnerability Type
N/A