| ଶୀର୍ଷକ | Open source HMS-PHP has two SQL injection vulnerabilities |
|---|
| ବର୍ଣ୍ଣନା | The front end post requests to transfer the uname and pass to the back end and assign values to $username and $password respectively.
Without filtering, directly bring $username and $password into the database for verification with the username and password in the database.
However, the variable is controllable, and the account and password entered in the input box are brought into the database to execute SQL statements, resulting in SQL injection vulnerabilities. |
|---|
| ଉତ୍ସ | ⚠️ https://github.com/Pingkon/HMS-PHP/issues/1 |
|---|
| ଉପଭୋକ୍ତା | ace. (UID 34853) |
|---|
| ଦାଖଲ | 11/09/2022 07:51 AM (3 ବର୍ଷ ବର୍ଷ ago) |
|---|
| ମଧ୍ୟମ ଧରଣର | 11/13/2022 09:26 AM (4 days later) |
|---|
| ସ୍ଥିତି | ଗ୍ରହଣ କରାଯାଇଛି |
|---|
| VulDB ଏଣ୍ଟ୍ରି | 213551 [Pingkon HMS-PHP admin/adminlogin.php uname/pass SQL ଇଞ୍ଜେକ୍ସନ] |
|---|
| ପଏଣ୍ଟ | 20 |
|---|