在 girishsaraf 的 Online-Appointment-Booking-System(在线预约预订系统)中,发现了一个漏洞,影响范围截至提交版本 f427b4757128ca253d33d0cc4e87bbb9c999a4d5。该漏洞涉及组件“Login Handler”中的文件 Admin/mlogin.php 内的 mysqli_query 函数。通过操纵参数 uname/pass,可导致 SQL 注入攻击。该攻击可从远程发起。相关利用代码已公开,可被实际利用。 该产品采用滚动发布模型以提供持续更
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| girishsaraf | Online-Appointment-Booking-System | f427b4757128ca253d33d0cc4e87bbb9c999a4d5 |
cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet