Online Library System是一个开源在线图书馆系统。 SourceCodester Online Library System 1.0 版本存在SQL注入漏洞,该漏洞源于 admin/books/controller.php 文件的 IBSN 参数存在 SQL 注入漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Online Library System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-3359 | 7.3 HIGH | SourceCodester Online Library System login.php sql injection |
| CVE-2024-3360 | 7.3 HIGH | SourceCodester Online Library System index.php sql injection |
| CVE-2024-3361 | 7.3 HIGH | SourceCodester Online Library System deweydecimal.php sql injection |
| CVE-2024-3363 | 7.3 HIGH | SourceCodester Online Library System index.php sql injection |
| CVE-2024-3376 | 7.3 HIGH | SourceCodester Computer Laboratory Management System config.php redirect |
| CVE-2024-3413 | 7.3 HIGH | SourceCodester Human Resource Information System login_process.php sql injection |
| CVE-2024-3377 | 4.3 MEDIUM | SourceCodester Computer Laboratory Management System cross site scripting |
| CVE-2024-3358 | 3.5 LOW | SourceCodester Aplaya Beach Resort Online Reservation System index.php cross site scriptin |
| CVE-2024-3364 | 3.5 LOW | SourceCodester Online Library System index.php cross site scripting |
| CVE-2024-3365 | 3.5 LOW | SourceCodester Online Library System controller.php cross site scripting |
| CVE-2024-3414 | 3.5 LOW | SourceCodester Human Resource Information System addcorporate_process.php cross site scrip |
| CVE-2024-3415 | 3.5 LOW | SourceCodester Human Resource Information System addbranches_process.php cross site script |
No comments yet