在 girishsaraf 的 Online-Appointment-Booking-System 系统中,截至 commit 哈希 f427b4757128ca253d33d0cc4e87bbb9c999a4d5,发现了一个安全漏洞。该问题影响“医生搜索端点”(Doctor Search Endpoint)组件中 locateus.php 文件内的 mysqli_query 函数。通过对参数 doctorname 进行构造利用,可引发 SQL 注入攻击。该漏洞可被远程利用。目前已有公开的利用代码(EXP),存在被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| girishsaraf | Online-Appointment-Booking-System | f427b4757128ca253d33d0cc4e87bbb9c999a4d5 |
cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105387 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_query sql inj |
| CVE-2026-105468 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection |
| CVE-2026-105469 | 7.3 HIGH | girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection |
No comments yet