在 code-projects 车辆管理系统 1.0 版本中检测到一个漏洞。受影响的元素是文件 中的一个未知函数。对参数 进行操纵可导致 SQL 注入。该攻击可远程发起。利用方式现已公开,可被用于实际利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| code-projects | Vehicle Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Vehicle Management System | 1.0 |
cpe:2.3:a:code-projects:vehicle_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85397 | 7.3 HIGH | code-projects Hospital Information System addReq.php findBySearch sql injection |
| CVE-2026-85398 | 7.3 HIGH | code-projects Hospital Information System viewReq.php viewReq sql injection |
| CVE-2026-85399 | 7.3 HIGH | code-projects Hospital Information System PrespController.php getSinglePresp sql injection |
| CVE-2026-85402 | 7.3 HIGH | code-projects Doctor Appointment System booking.php sql injection |
| CVE-2026-85403 | 7.3 HIGH | code-projects Doctor Appointment System contactus.php sql injection |
| CVE-2026-85517 | 5.3 MEDIUM | code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql in |
| CVE-2026-85643 | 4.7 MEDIUM | code-projects Online Shopping System adduser.php mysqli_query sql injection |
No comments yet