在其sourcecode在线招生系统1.0版本中发现了一个漏洞。此问题影响了register1.php文件的未知处理过程。通过操纵参数fname可导致SQL注入攻击。该攻击可通过远程方式实施。相关利用工具已公开,可能被恶意利用。 (翻译说明: 1. "itsourcecode"作为专有名词保留不译 2. "Online Admission System"译为行业通用的"在线招生系统" 3. "unknown processing"采用"未知处理过程"的准确表述 4. "manipulation"译为安全领域常用的"
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Online Admission System | 1.0 |
cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105185 | 7.3 HIGH | itsourcecode Online Admission System examinee.php sql injection |
| CVE-2026-105184 | 7.3 HIGH | itsourcecode Online Admission System creteria.php sql injection |
| CVE-2026-105183 | 7.3 HIGH | itsourcecode Online Admission System confirm.php sql injection |
| CVE-2026-105172 | 7.3 HIGH | itsourcecode Online Admission System login1.php sql injection |
| CVE-2026-105187 | 6.3 MEDIUM | itsourcecode Online Admission System key.php sql injection |
| CVE-2026-105186 | 6.3 MEDIUM | itsourcecode Online Admission System new.php sql injection |
No comments yet