Simple Online Bidding System是oretnom23个人开发者的一个在线投标系统。 Simple Online Bidding System 1.0版本存在SQL注入漏洞,该漏洞源于对参数username的错误操作会导致sql注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Online Bidding System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-7798 | 7.3 HIGH | SourceCodester Simple Online Bidding System ajax.php sql injection |
| CVE-2024-7800 | 6.3 MEDIUM | SourceCodester Simple Online Bidding System ajax.php sql injection |
| CVE-2024-7792 | 6.3 MEDIUM | SourceCodester Task Progress Tracker delete-task.php sql injection |
| CVE-2024-7754 | 6.3 MEDIUM | SourceCodester Clinics Patient Management System check_medicine_name.php sql injection |
| CVE-2024-7799 | 5.3 MEDIUM | SourceCodester Simple Online Bidding System users.php improper authorization |
| CVE-2024-7753 | 5.3 MEDIUM | SourceCodester Clinics Patient Management System user_images direct request |
| CVE-2024-7793 | 3.5 LOW | SourceCodester Task Progress Tracker add-task.php cross site scripting |
No comments yet