Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection
Vulnerability Description
A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/faculty_sched.php. The manipulation of the argument faculty with the input ' OR (SELECT 2078 FROM(SELECT COUNT(*),CONCAT(0x716a717071,(SELECT (ELT(2078=2078,1))),0x717a706a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- uYCM leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205831.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Online Class and Exam Scheduling System SQL注入漏洞
Vulnerability Description
Online Class and Exam Scheduling System是一款在线课程和考试安排系统。 Online Class and Exam Scheduling System 1.0存在SQL注入漏洞,该漏洞源于文件/pages/faculty_sched.php的未知函数受到影响。操作参数faculty会导致sql注入。攻击可以远程发起,该漏洞利用已向公众披露并可能被使用。
CVSS Information
N/A
Vulnerability Type
N/A