Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-71120
HistoryFeb 28, 2022 - 12:00 a.m.

BloofoxCms SQL Injection Vulnerability

2022-02-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
bloofoxcms
php
sql injection
security vulnerability
database theft.

EPSS

0.002

Percentile

54.2%

BloofoxCms, a Php-based text content management system, is vulnerable to SQL injection in versions 0.5.1 (inclusive) to 0.5.2.1 (inclusive), due to the following parameters β€œURLs,lang_id,tmpl_id,mod_rewrite,eta_ doctype,meta_charset,default_group,page group” lacks validation for external input SQL statements. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.2%

Related for CNVD-2022-71120