Event Registration System是Carlo Montero个人开发者的一个带有 QR 码的事件注册系统。 Event Registration System 1.0版本存在SQL注入漏洞,该漏洞源于/registrar/ 中存在未知函数,通过参数 search 导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Event Registration System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-5118 | 7.3 HIGH | SourceCodester Event Registration System login.php sql injection |
| CVE-2024-5117 | 7.3 HIGH | SourceCodester Event Registration System portal.php sql injection |
| CVE-2024-5116 | 7.3 HIGH | SourceCodester Online Examination System save.php sql injection |
| CVE-2024-5145 | 6.3 MEDIUM | SourceCodester Vehicle Management System HTTP POST Request newdriver.php unrestricted uplo |
| CVE-2024-5134 | 6.3 MEDIUM | SourceCodester Electricity Consumption Monitoring Tool delete-bill.php sql injection |
| CVE-2024-5120 | 6.3 MEDIUM | SourceCodester Event Registration System sql injection |
| CVE-2024-5119 | 6.3 MEDIUM | SourceCodester Event Registration System sql injection |
| CVE-2024-5123 | 4.3 MEDIUM | SourceCodester Event Registration System cross site scripting |
| CVE-2024-5121 | 3.5 LOW | SourceCodester Event Registration System cross site scripting |
No comments yet