Beveiligingsadvies

CVE-2018-18529

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-10-19 20:00:00
Laatst bijgewerkt 2024-09-16 22:20:52
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.