从这个网页截图中可以获取到以下关于漏洞的关键信息: 漏洞信息 EDB-ID: 48545 CVE: N/A Author: Gus Ralph Type: WEBAPPS Platform: PHP Date: 2020-06-04 Vulnerable App: Navigate CMS 2.8.7 EDB Verified: No 漏洞描述 Exploit Title: Navigate CMS 2.8.7 - 'sidx' SQL Injection (Authenticated) Vendor Homepage: https://www.navigatecms.com/en/home Software Link: https://sourceforge.net/projects/navigatecms/files/releases/navigate-2.8.7r1401.zip/download Tested on: Ubuntu CVE: N/A 漏洞影响 Impact: This script will leak the "activation_key" value for the user whose ID is set to 1 in the database. The activation key can be used to reset that user's password to whatever you want, bypassing the need to crack a hash. An example password reset URL would be: Python代码片段 其他信息 Advisory/Source: Link