在 SourceCodester Photo Share Website 1.0 中发现了一个漏洞。受影响的组件是文件 /social/ajax.php?action=login 中的一个未知函数。对参数 email 的操作可导致 SQL 注入。该攻击可以远程发起,且相关利用代码已经公开,可能被恶意利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Photo Share Website | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Photo Share Website | 1.0 |
cpe:2.3:a:sourcecodester:photo_share_website:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: SQLi in /social/ajax.php login extracted secret PROOF_f3e8935561de4f50 via UNION SELECT (response user field)
| CVE-2026-19231 | 7.3 HIGH | SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection |
| CVE-2026-19211 | 7.3 HIGH | SourceCodester Photo Share Website ajax.php signup sql injection |
| CVE-2026-19210 | 6.3 MEDIUM | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload |
| CVE-2026-19229 | 5.3 MEDIUM | SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information di |
| CVE-2026-19230 | 3.5 LOW | SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scrip |
| CVE-2026-19209 | 3.5 LOW | SourceCodester Photo Share Website index.php home cross site scripting |
No comments yet