漏洞标题
Campcodes Retro Cellphone Online Store modal_add_product.php sql 注入
漏洞描述信息
Campcodes复古手机在线商店modal_add_product.php SQL注入
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Campcodes Retro Cellphone Online Store modal_add_product.php sql injection
漏洞描述信息
A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/modal_add_product.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230580.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Campcodes Retro Cellphone Online Store SQL注入漏洞
漏洞描述信息
Campcodes Retro Cellphone Online Store是Campcodes公司的一个复古手机在线商店。 Campcodes Retro Cellphone Online Store 1.0版本存在SQL注入漏洞,该漏洞源于/admin/modal_add_product.php 中存在未知函数,通过参数category导致 sql 注入。
CVSS信息
N/A
漏洞类别
SQL注入