SourceCodester Web-based Pharmacy Product Management System是SourceCodester开源的一个基于 Web 的药房产品管理系统。 SourceCodester Web-based Pharmacy Product Management System 1.0版本存在命令注入漏洞,该漏洞源于对文件backup.php中参数txtdbname的错误操作导致操作系统命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Web-based Pharmacy Product Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-3694 | 7.3 HIGH | SourceCodester Web-based Pharmacy Product Management System Login sql injection |
| CVE-2025-3696 | 6.3 MEDIUM | SourceCodester Web-based Pharmacy Product Management System search_stock. php sql injectio |
| CVE-2025-3697 | 6.3 MEDIUM | SourceCodester Web-based Pharmacy Product Management System edit-product.php sql injection |
| CVE-2025-3728 | 5.3 MEDIUM | SourceCodester Simple Hotel Booking System login buffer overflow |
| CVE-2025-3692 | 2.4 LOW | SourceCodester Online Eyewear Shop Master.php cross site scripting |
No comments yet