CVE-2018-18546
21.10.2018, 01:29
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.
Vendor | Product | Version |
---|---|---|
thinkphp | thinkphp | 3.2.4 |
𝑥
= Vulnerable software versions
References