漏洞类别:CGI
漏洞等级:
漏洞信息
sysPass is a password manager that allows to save passwords using bidirectional encryption with a master password to a database. A SQL Injection vulnerability in ajax_search.php allows remote, authenticated users to execute arbitrary SQL queries.
Affected Versions:
sysPass 1.0.9 and earlier
漏洞危害
An authenticated remote user could exploit this vulnerability to run arbitrary SQL queries on the system and retrieve sensitive information.
解决方案
0day
文章评论