在 itsourcecode Online Admission System 1.0 版本中发现了一个漏洞。该问题影响对文件 /admin/login1.php 的某些未明确处理的逻辑。其中,User 参数的处理存在缺陷,可导致 SQL 注入攻击。该漏洞可由远程发起,相关利用代码已公开披露,可能被攻击者利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Online Admission System Project | 1.0 |
cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105185 | 7.3 HIGH | itsourcecode Online Admission System examinee.php sql injection |
| CVE-2026-105184 | 7.3 HIGH | itsourcecode Online Admission System creteria.php sql injection |
| CVE-2026-105183 | 7.3 HIGH | itsourcecode Online Admission System confirm.php sql injection |
| CVE-2026-105172 | 7.3 HIGH | itsourcecode Online Admission System login1.php sql injection |
| CVE-2026-105254 | 6.3 MEDIUM | itsourcecode Online Admission System schoolyear.php sql injection |
| CVE-2026-105187 | 6.3 MEDIUM | itsourcecode Online Admission System key.php sql injection |
| CVE-2026-105186 | 6.3 MEDIUM | itsourcecode Online Admission System new.php sql injection |
| CVE-2026-105181 | 6.3 MEDIUM | itsourcecode Online Admission System register1.php sql injection |
No comments yet