CVE-2018-16385: SQL Injection
Published Sep 3, 2018
·Updated
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
Other sources
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
Affected Software
2 affected componentsFixes available
composer/topthink/framework<5.1.23
5.1.23
ThinkPHP ThinkPHP<5.1.23
Event History
Sep 3, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·02:03 AM
Frequently Asked Questions
1
What is the vulnerability ID for ThinkPHP before 5.1.23?
The vulnerability ID for ThinkPHP before 5.1.23 is CVE-2018-16385.
2
What is the severity of CVE-2018-16385?
The severity of CVE-2018-16385 is critical, with a score of 9.8.
3
How does ThinkPHP before 5.1.23 allow SQL Injection?
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
4
What software versions are affected by CVE-2018-16385?
ThinkPHP versions up to 5.1.23 are affected by CVE-2018-16385.
5
Where can I find more information about CVE-2018-16385?
More information about CVE-2018-16385 can be found at the following references: [Vulnerability Details](https://exchange.xforce.ibmcloud.com/vulnerabilities/149288), [GitHub Issue](https://github.com/top-think/framework/issues/1375).