### 漏洞关键信息总结 - **漏洞ID**: - VDB-226105 - CVE-2023-2097 - GCVE-100-226105 - **系统与版本**: - SourceCodester Vehicle Service Management System 1.0 - **漏洞类型**: - SQL Injection (CWE-89) - **影响文件**: - `/classes/Master.php` - **漏洞严重等级**: - Critical - **攻击向量**: - Remote exploitation is possible - **漏洞描述**: - Manipulation of the argument `id` with an unknown input causes SQL injection. - **影响**: - Known to affect confidentiality, integrity, and availability. - **公开信息**: - Vulnerability disclosed on 04/15/2023 - Public exploit and technical details available on GitHub - Possible to find vulnerable targets via Google Hacking with query `inurl:classes/Master.php` - **建议措施**: - Replace the affected object with an alternative product. - No specific countermeasures known.