漏洞关键信息 基本信息: EDB-ID: 47460 CVE: N/A Author: Carlos Avila Type: Webapps Platform: PHP Date: 2019-10-04 漏洞描述: Exploit Title: LabCollector (Laboratory Information System) 5.423 - Multiples SQL Injection Software Links/Project: https://www.labcollector.com/clientarea/downloads.php Version: LabCollector (Laboratory Information System) 5.423 Exploit Author: Carlos Avila Category: Webapps Tested on: Debian 9 / Win10 Contact: http://twitter.com/badboy_nt 影响的应用: LabCollector Lab Services Manager (LSM) is a network-based application that helps laboratories, core facilities, biotechs providing services to clients or partners to keep track of samples arriving for processing, track status and generate reports. Billing management is also possible. LSM is a simple and complete lab services LIMS software. 漏洞详情: Description: 多个SQL注入漏洞 Post Request: 显示了具体的POST请求细节,包括HTTP头和参数,用于登录页面的SQL注入攻击。 Solution: 应用程序输入必须在整个项目开发过程中正确验证。 测试环境: 所有测试都在受控和本地环境中进行。 参考资料: 提供了使用 工具进行SQL注入测试的命令示例。