漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SQL Injection in extension "News system" (news)
Vulnerability Description
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
TYPO3 Extension News system SQL注入漏洞
Vulnerability Description
TYPO3 Extension News system是TYPO3开源的一个TYPO3新闻与内容发布扩展。 TYPO3 Extension News system存在SQL注入漏洞,该漏洞源于用户输入清理不足,可能导致未经身份验证的攻击者通过URL参数注入任意SQL。
CVSS Information
N/A
Vulnerability Type
N/A