Code-Projects AVL Rooms是Code-Projects开源的一个AVL房间系统。 Code-Projects AVL Rooms 1.0版本存在安全漏洞,该漏洞源于文件/city.php中参数city的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | AVL Rooms | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/sunhuiHi666/CVE-2025-7606 | POC Details |
| CVE-2025-7611 | 7.3 HIGH | code-projects Wedding Reservation global.php sql injection |
| CVE-2025-7587 | 7.3 HIGH | code-projects Online Appointment Booking System cover.php sql injection |
| CVE-2025-7593 | 7.3 HIGH | code-projects Job Diary view-all.php sql injection |
| CVE-2025-7594 | 7.3 HIGH | code-projects Job Diary view-emp.php sql injection |
| CVE-2025-7595 | 7.3 HIGH | code-projects Job Diary view-cad.php sql injection |
| CVE-2025-7605 | 7.3 HIGH | code-projects AVL Rooms profile.php sql injection |
| CVE-2025-7607 | 7.3 HIGH | code-projects Simple Shopping Cart save_order.php sql injection |
| CVE-2025-7608 | 7.3 HIGH | code-projects Simple Shopping Cart userlogin.php sql injection |
| CVE-2025-7609 | 7.3 HIGH | code-projects Simple Shopping Cart register.php sql injection |
| CVE-2025-7610 | 7.3 HIGH | code-projects Electricity Billing System change_password.php sql injection |
| CVE-2025-7612 | 7.3 HIGH | code-projects Mobile Shop login.php sql injection |
| CVE-2025-7581 | 6.3 MEDIUM | code-projects Voting System positions_edit.php sql injection |
| CVE-2025-7580 | 6.3 MEDIUM | code-projects Voting System positions_row.php sql injection |
| CVE-2025-7558 | 6.3 MEDIUM | code-projects Voting System positions_add.php sql injection |
| CVE-2025-7557 | 6.3 MEDIUM | code-projects Voting System voters_row.php sql injection |
| CVE-2025-7556 | 6.3 MEDIUM | code-projects Voting System voters_edit.php sql injection |
| CVE-2025-7555 | 6.3 MEDIUM | code-projects Voting System voters_add.php sql injection |
No comments yet