Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2018-18529
- EPSS 0.26%
- Published 19.10.2018 20:29:00
- Last modified 21.11.2024 03:56:06
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.
9.8
CVE-2018-17566
- EPSS 0.26%
- Published 26.09.2018 21:29:02
- Last modified 21.11.2024 03:54:37
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
9.8
CVE-2018-16385
- EPSS 0.55%
- Published 03.09.2018 02:29:00
- Last modified 21.11.2024 03:52:38
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
9.8
CVE-2018-10225
- EPSS 0.26%
- Published 19.04.2018 08:29:00
- Last modified 21.11.2024 03:41:03
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.