漏洞标题
SourceCodester学生学习中心桌面管理系统manage_student.php SQL注入
漏洞描述信息
源码极客学生学习中心前台管理系统 manage_student.php SQL注入
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
SourceCodester Student Study Center Desk Management System manage_student.php sql injection
漏洞描述信息
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Student Study Center Desk Management System SQL注入漏洞
漏洞描述信息
Student Study Center Desk Management System是学生学习中心课桌管理系统。 Student Study Center Desk Management System 1.0版本存在SQL注入漏洞,该漏洞源于该漏洞源于文件manage_student.php存在问题,对参数id的操作会导致sql注入。
CVSS信息
N/A
漏洞类别
SQL注入