SourceCodester Gym Management System是美国SourceCodester公司的一个体育馆管理建站系统。该系统由C和 sql server 为开发技术,具备客户和供应商管理、产品管理、销售管理 、体育馆会员管理 、健身评估 、系统日志、数据库备份和还原等功能。 Gym Management System存在SQL注入漏洞,该漏洞源于Exercises Module的未知部分受到影响,对参数exer的操纵会导致sql注入。攻击可以远程发起,该漏洞利用已向公众披露并可能被使
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Gym Management System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2702 | 7.3 HIGH | SourceCodester Company Website CMS Cookie site-settings.php access control |
| CVE-2022-2699 | 6.3 MEDIUM | SourceCodester Simple E-Learning System claire_blake sql injection |
| CVE-2022-2705 | 6.3 MEDIUM | SourceCodester Simple Student Information System manage_department.php sql injection |
| CVE-2022-2706 | 6.3 MEDIUM | SourceCodester Online Class and Exam Scheduling System class_sched.php sql injection |
| CVE-2022-2707 | 6.3 MEDIUM | SourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection |
| CVE-2022-2708 | 5.5 MEDIUM | SourceCodester Gym Management System login.php sql injection |
| CVE-2022-2700 | 4.7 MEDIUM | SourceCodester Gym Management System GET Parameter sql injection |
| CVE-2022-2704 | 4.3 MEDIUM | SourceCodester Simple E-Learning System downloadFiles.php information disclosure |
| CVE-2022-2701 | 3.5 LOW | SourceCodester Simple E-Learning System claire_blake cross site scripting |
No comments yet