Code-Projects Online Product Reservation System是Code-Projects开源的一个在线产品预订系统。 Code-Projects Online Product Reservation System 1.0版本存在SQL注入漏洞,该漏洞源于文件/handgunner-administrator/prod.php中参数cat/price/name/model/serial的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Product Reservation System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-0575 | 7.3 HIGH | code-projects Online Product Reservation System Administrator Login adminlogin.php sql inj |
| CVE-2026-0578 | 7.3 HIGH | code-projects Online Product Reservation System delete.php sql injection |
| CVE-2026-0579 | 7.3 HIGH | code-projects Online Product Reservation System POST Parameter edit.php sql injection |
| CVE-2026-0577 | 6.3 MEDIUM | code-projects Online Product Reservation System prod.php unrestricted upload |
No comments yet