Webkil QloApps是免费的开源酒店预订和在线预订系统。 Webkul QloApps 1.6.0版本存在安全漏洞,该漏洞源于GET参数存在SQL注入漏洞。攻击者可利用该漏洞绕过 Web应用程序的身份验证和授权机制并检索整个数据库的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameters date_from, date_to, and id_product allows a remote attacker to retrieve the contents of an entire database. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-36284.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-36287 | Webkul QloApps 跨站脚本漏洞 | |
| CVE-2023-27908 | Autodesk Installer 代码问题漏洞 | |
| CVE-2023-34188 | Cesanta Mongoose 安全漏洞 | |
| CVE-2023-34203 | Progress OpenEdge 注入漏洞 | |
| CVE-2023-35759 | Progress Software WhatsUp Gold 跨站脚本漏洞 | |
| CVE-2023-36345 | POS Codekop 跨站脚本漏洞 | |
| CVE-2023-36346 | POS Codekop 跨站脚本漏洞 | |
| CVE-2023-36348 | POS Codekop 安全漏洞 | |
| CVE-2023-3212 | Linux kernel 代码问题漏洞 | |
| CVE-2023-34671 | Elenos ETG150 安全漏洞 | |
| CVE-2023-3317 | Linux kernel 资源管理错误漏洞 | |
| CVE-2023-25003 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2023-34672 | Elenos ETG150 FM transmitter 安全漏洞 | |
| CVE-2023-34673 | Elenos ETG150 安全漏洞 | |
| CVE-2023-36193 | Gifsicle 缓冲区错误漏洞 | |
| CVE-2023-36271 | GNU LibreDWG 缓冲区错误漏洞 | |
| CVE-2023-36272 | LibreDWG 缓冲区错误漏洞 | |
| CVE-2023-36273 | GNU LibreDWG 缓冲区错误漏洞 | |
| CVE-2023-36274 | GNU LibreDWG 缓冲区错误漏洞 | |
| CVE-2023-36288 | Webkul QloApps 跨站脚本漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet