在 code-projects 在线购物系统 1.0 版本中发现了一个缺陷。受影响的函数是文件 admin/adduser.php 中的 mysqli_query。通过对参数 mobile 进行操控,可能引发 SQL 注入漏洞。该攻击可远程发起。漏洞利用方法已公开,可能被实际利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| code-projects | Online Shopping System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Shopping System | 1.0 |
cpe:2.3:a:code-projects:online_shopping_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85397 | 7.3 HIGH | code-projects Hospital Information System addReq.php findBySearch sql injection |
| CVE-2026-85398 | 7.3 HIGH | code-projects Hospital Information System viewReq.php viewReq sql injection |
| CVE-2026-85399 | 7.3 HIGH | code-projects Hospital Information System PrespController.php getSinglePresp sql injection |
| CVE-2026-85402 | 7.3 HIGH | code-projects Doctor Appointment System booking.php sql injection |
| CVE-2026-85403 | 7.3 HIGH | code-projects Doctor Appointment System contactus.php sql injection |
| CVE-2026-85516 | 7.3 HIGH | code-projects Vehicle Management System busprofile.php sql injection |
| CVE-2026-85517 | 5.3 MEDIUM | code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql in |
No comments yet