Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL injection in Janobe E-Negosyo System
Vulnerability Description
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Young Entrepreneur E-Negosyo System SQL注入漏洞
Vulnerability Description
Young Entrepreneur E-Negosyo System是janobe个人开发者的一个青年企业家电子 Negosyo 系统。 Young Entrepreneur E-Negosyo System 1.0版本存在SQL注入漏洞。攻击者利用该漏洞可以向服务器发送特制查询并检索“/admin/orders/controller.php”的“id”中存储的所有信息。
CVSS Information
N/A
Vulnerability Type
N/A