SourceCodester Garage Management System(Cms-Website)是mayuri_k个人开发者的一个车库管理系统。可帮助您管理所有车辆、汽车和摩托车。 Garage Management System 1.0存在安全漏洞,该漏洞源于影响到文件/login.php的未知代码。通过输入特殊字符串对参数用户名进行操作会导致 sql 注入。该攻击可以远程发起。该漏洞已向公众披露并可能被使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Garage Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Garage Management System 1.0 contains a SQL injection vulnerability in /login.php via manipulation of the argument username with input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2467.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet