Il BSEN ordinare il software 1.0 ha SQL Injection attraverso studente / index.php? View = view & id = [SQL] o index.php? Q = single-item & id = [SQL]. |
https://www.exploit-db.com/exploits/45730/ http://packetstormsecurity.com/files/150017/E-Negosyo-System-1.0-SQL-Injection.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18801 |
Vulnerabilità: CVE-2018-18801
