漏洞标题
code-projects Admission Management System signupconfirm.php SQL注入漏洞
漏洞描述信息
在代码项目 Admission Management System 1.0 中发现了一个被归类为关键级别的漏洞。此漏洞影响了文件 /signupconfirm.php 中的未知功能。对参数 in_eml 的操作可能导致 SQL 注入。该攻击可以从远程发起。漏洞的利用方法已经公开,可能被利用。其他参数也可能受到影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
code-projects Admission Management System signupconfirm.php sql injection
漏洞描述信息
A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /signupconfirm.php. The manipulation of the argument in_eml leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Code-Projects Admission Management System 注入漏洞
漏洞描述信息
Code-Projects Admission Management System是Code-Projects开源的一个招生管理系统。 Code-Projects Admission Management System 1.0版本存在注入漏洞,该漏洞源于文件/signupconfirm.php的参数in_eml会导致SQL注入。
CVSS信息
N/A
漏洞类别
注入