Security Advisory

CVE-2018-18529

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-10-19 20:00:00
Last updated 2024-09-16 22:20:52
Assigner mitre
State PUBLISHED

Description

ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.