在 girishsaraf 的 Online-Appointment-Booking-System(在线预约系统)中,从初始提交至 f427b4757128ca253d33d0cc4e87bbb9c999a4d5 版本期间,存在一个安全漏洞。该漏洞影响组件 AJAX Endpoint 中文件 get_town.php 的未知代码部分。通过对参数 countryid/townid/cid/didval/cidval 进行操纵,可能导致 SQL 注入攻击。攻击者可远程发起该攻击。 目前,该漏洞的利用方式已被公开披露,并
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| girishsaraf | Online-Appointment-Booking-System | f427b4757128ca253d33d0cc4e87bbb9c999a4d5 |
cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105387 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_query sql inj |
| CVE-2026-105468 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection |
| CVE-2026-105470 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus.php mysqli_q |
No comments yet