漏洞标题
1000 Projects Campaign Management System Platform for Women sc_login.php 存在SQL注入漏洞
漏洞描述信息
在1000 Projects Campaign Management System Platform for Women 1.0版本中发现了一个漏洞,该漏洞被评定为严重级别。此漏洞影响了文件/Code/sc_login.php中的未知功能。通过操纵参数uname可以导致SQL注入。攻击者可以在远程进行此攻击。该漏洞的利用方法已经公开,有可能被利用。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
1000 Projects Campaign Management System Platform for Women sc_login.php sql injection
漏洞描述信息
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
1000 Projects Campaign Management System Platform for Women 安全漏洞
漏洞描述信息
1000 Projects Campaign Management System Platform for Women是1000 Projects开源的一个活动管理系统平台。 1000 Projects Campaign Management System Platform for Women 1.0版本存在安全漏洞,该漏洞源于文件/Code/sc_login.php的参数uname会导致SQL注入。
CVSS信息
N/A
漏洞类别
其他