Code-Projects Online Product Reservation System是Code-Projects开源的一个在线产品预订系统。 Code-Projects Online Product Reservation System 1.0版本存在SQL注入漏洞,该漏洞源于对文件app/products/left_cart.php中参数ID的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Product Reservation System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0583 | 7.3 HIGH | code-projects Online Product Reservation System User Login login.php sql injection |
| CVE-2026-0585 | 7.3 HIGH | code-projects Online Product Reservation System GET Parameter order_view.php sql injection |
| CVE-2026-0589 | 7.3 HIGH | code-projects Online Product Reservation System Administration Backend improper authentica |
| CVE-2026-0592 | 7.3 HIGH | code-projects Online Product Reservation System User Registration register_code.php sql in |
| CVE-2026-0605 | 7.3 HIGH | code-projects Online Music Site login.php sql injection |
| CVE-2026-0606 | 7.3 HIGH | code-projects Online Music Site Albums.php sql injection |
| CVE-2026-0607 | 7.3 HIGH | code-projects Online Music Site AdminViewSongs.php sql injection |
| CVE-2026-0590 | 6.3 MEDIUM | code-projects Online Product Reservation System POST Parameter delete.php sql injection |
| CVE-2026-0591 | 6.3 MEDIUM | code-projects Online Product Reservation System Cart Update update.php sql injection |
| CVE-2026-0586 | 4.3 MEDIUM | code-projects Online Product Reservation System prod.php cross site scripting |
No comments yet