Open ISES Project是Open ISES公司的一个面向应急服务机构的开源信息化软件与资源平台。 Open ISES Project 3.30A版本存在SQL注入漏洞,该漏洞源于通过p1参数注入恶意代码,可能导致未经身份验证的攻击者执行任意SQL查询,提取敏感数据库信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Open ISES | Open ISES Project | 3.30A |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Open ISES | Open ISES Project | 3.30A | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-25404 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via add_facnote.php |
| CVE-2018-25402 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via inc_types_graph.php |
| CVE-2018-25398 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via main.php |
| CVE-2018-25400 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via form_post.php |
| CVE-2018-25403 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via city_graph.php |
| CVE-2018-25399 | 8.2 HIGH | The Open ISES Project 3.30A SQL Injection via nearby.php |
No comments yet