在其sourcecode在线招生系统1.0版本中发现了一个漏洞。该漏洞影响了文件/admin/examinee.php中的某个未知函数。通过对参数ID进行操控,可以导致SQL注入攻击。此攻击可以从远程发起,目前相关漏洞利用代码已经公开,可能被他人利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Online Admission System | 1.0 |
cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105184 | 7.3 HIGH | itsourcecode Online Admission System creteria.php sql injection |
| CVE-2026-105183 | 7.3 HIGH | itsourcecode Online Admission System confirm.php sql injection |
| CVE-2026-105172 | 7.3 HIGH | itsourcecode Online Admission System login1.php sql injection |
| CVE-2026-105187 | 6.3 MEDIUM | itsourcecode Online Admission System key.php sql injection |
| CVE-2026-105186 | 6.3 MEDIUM | itsourcecode Online Admission System new.php sql injection |
| CVE-2026-105181 | 6.3 MEDIUM | itsourcecode Online Admission System register1.php sql injection |
No comments yet