在 Alex Tselegidis EasyAppointments <= 1.5.1 版本的 /customers/search 接口中,order_by 参数存在 SQL 注入漏洞。该漏洞源于未经验证和过滤的用户输入被直接传入 CodeIgniter 查询构建器(Query Builder)的 order_by 方法,从而导致攻击者可执行基于时间的盲注查询,并枚举数据库结构信息。在某些 MySQL 配置下,此漏洞还可能通过 INTO OUTFILE 写入 PHP 后门文件,进而实现远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-51077 | DesDev DedeCMS 安全漏洞 | |
| CVE-2026-51078 | dedecms 安全漏洞 | |
| CVE-2026-51564 | giuliopanda Milk admin 安全漏洞 | |
| CVE-2021-32084 | Quest KACE Systems Deployment Appliance 安全漏洞 | |
| CVE-2021-32088 | Quest KACE Systems Deployment Appliance 安全漏洞 | |
| CVE-2021-32086 | Quest KACE Systems Deployment Appliance 安全漏洞 | |
| CVE-2021-32087 | Quest KACE Systems Deployment Appliance 安全漏洞 | |
| CVE-2021-32085 | Quest KACE Systems Deployment Appliance 安全漏洞 | |
| CVE-2026-51565 | giuliopanda Milk admin 安全漏洞 | |
| CVE-2025-63913 | RISC-V Open Source Supervisor Binary Interface 安全漏洞 |
No comments yet