在 code-projects 的车辆管理系统 1.0 中发现一个缺陷。受影响的部分是组件“SQL 数据库备份文件处理器”中 文件的未知功能。通过执行特定操作可能导致信息泄露。该攻击可远程发起,且漏洞利用方式已公开并可能已被使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| code-projects | Vehicle Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Vehicle Management System | 1.0 |
cpe:2.3:a:code-projects:vehicle_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85397 | 7.3 HIGH | code-projects Hospital Information System addReq.php findBySearch sql injection |
| CVE-2026-85398 | 7.3 HIGH | code-projects Hospital Information System viewReq.php viewReq sql injection |
| CVE-2026-85399 | 7.3 HIGH | code-projects Hospital Information System PrespController.php getSinglePresp sql injection |
| CVE-2026-85402 | 7.3 HIGH | code-projects Doctor Appointment System booking.php sql injection |
| CVE-2026-85403 | 7.3 HIGH | code-projects Doctor Appointment System contactus.php sql injection |
| CVE-2026-85516 | 7.3 HIGH | code-projects Vehicle Management System busprofile.php sql injection |
| CVE-2026-85643 | 4.7 MEDIUM | code-projects Online Shopping System adduser.php mysqli_query sql injection |
No comments yet