code-projects Faculty Management System 1.0 /admin/php/crud.php fieldname/tablename एसक्यूएल इंजेक्शन

एक कमकुवतपणा जो गंभीर म्हणून वर्गीकृत केला आहे, तो code-projects Faculty Management System 1.0 मध्ये आढळून आला आहे. या ठिकाणी परिणाम झाला आहे अज्ञात फंक्शन फाइल /admin/php/crud.php च्या. सॉफ्टवेअरमध्ये fieldname/tablename या आर्ग्युमेंटचे केलेले बदल एसक्यूएल इंजेक्शन यास कारणीभूत ठरतात. समस्या जाहीर करण्यासाठी CWE वापरल्यास CWE-89 येथे नेले जाते. ही कमतरता प्रसिद्ध करण्यात आली होती 24/12/2023. डाउनलोडसाठी सल्ला github.com वर शेअर केला आहे. ही दुर्बलता CVE-2023-7096 म्हणून ओळखली जाते. दूरवरून हा हल्ला घडवून आणता येतो. तांत्रिक तपशील दिलेले आहेत. यासाठी एक एक्स्प्लॉइट उपलब्ध आहे. शोषण सार्वजनिकपणे जाहीर झाले आहे आणि त्याचा वापर होऊ शकतो. सध्या USD $0-$5k इतका असू शकतो. MITRE ATT&CK प्रकल्प T1505 हल्ला तंत्रज्ञान म्हणून घोषित करतो. प्रूफ-ऑफ-कॉन्सेप्ट म्हणून हे घोषित केले गेले आहे. शोषण डाउनलोडसाठी github.com येथे शेअर केले आहे. 0-डे म्हणून त्याची अंदाजे भूमिगत किंमत $0-$5k होती. If you want to get best quality of vulnerability data, you may have to visit VulDB.

6 बदल · 117 डेटा पॉइंट्स

शेतअद्ययावत 1/5
18/01/2024 05:31 PM
अद्ययावत 2/5
18/01/2024 05:40 PM
अद्ययावत 3/5
11/12/2025 09:40 AM
अद्ययावत 4/5
11/12/2025 10:44 AM
अद्ययावत 5/5
11/12/2025 12:30 PM
software_vendorcode-projectscode-projectscode-projectscode-projectscode-projects
software_nameFaculty Management SystemFaculty Management SystemFaculty Management SystemFaculty Management SystemFaculty Management System
software_version1.01.01.01.01.0
software_file/admin/php/crud.php/admin/php/crud.php/admin/php/crud.php/admin/php/crud.php/admin/php/crud.php
software_argumentfieldnamefieldnamefieldname/tablenamefieldname/tablenamefieldname/tablename
vulnerability_cweCWE-89 (एसक्यूएल इंजेक्शन)CWE-89 (एसक्यूएल इंजेक्शन)CWE-89 (एसक्यूएल इंजेक्शन)CWE-89 (एसक्यूएल इंजेक्शन)CWE-89 (एसक्यूएल इंजेक्शन)
vulnerability_risk22222
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prHHHHH
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
cvss3_vuldb_iLLLLL
cvss3_vuldb_aLLLLL
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.mdhttps://github.com/Glunko/vulnerability/blob/main/Faculty-Management-System_sql.md
source_cveCVE-2023-7096CVE-2023-7096CVE-2023-7096CVE-2023-7096CVE-2023-7096
cna_responsibleVulDBVulDBVulDBVulDBVulDB
advisory_date1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)
software_typeProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management Software
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_auMMMMM
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiPPPPP
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_rlXXXXX
cvss2_vuldb_basescore5.85.85.85.85.8
cvss2_vuldb_tempscore5.05.05.05.05.0
cvss3_vuldb_basescore4.74.74.74.74.7
cvss3_vuldb_tempscore4.34.34.34.34.3
cvss3_meta_basescore4.76.46.46.46.4
cvss3_meta_tempscore4.36.36.36.36.3
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
cve_assigned1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)1703372400 (24/12/2023)
cve_nvd_summaryA vulnerability was found in code-projects Faculty Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/php/crud.php. The manipulation of the argument fieldname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248948.A vulnerability was found in code-projects Faculty Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/php/crud.php. The manipulation of the argument fieldname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248948.A vulnerability was found in code-projects Faculty Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/php/crud.php. The manipulation of the argument fieldname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248948.A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
cvss3_nvd_avNNNN
cvss3_nvd_acLLLL
cvss3_nvd_prNNNN
cvss3_nvd_uiNNNN
cvss3_nvd_sUUUU
cvss3_nvd_cHHHH
cvss3_nvd_iHHHH
cvss3_nvd_aHHHH
cvss2_nvd_avNNNN
cvss2_nvd_acLLLL
cvss2_nvd_auMMMM
cvss2_nvd_ciPPPP
cvss2_nvd_iiPPPP
cvss2_nvd_aiPPPP
cvss3_cna_avNNNN
cvss3_cna_acLLLL
cvss3_cna_prHHHH
cvss3_cna_uiNNNN
cvss3_cna_sUUUU
cvss3_cna_cLLLL
cvss3_cna_iLLLL
cvss3_cna_aLLLL
cve_cnaVulDBVulDBVulDBVulDB
cvss2_nvd_basescore5.85.85.85.8
cvss3_nvd_basescore9.89.89.89.8
cvss3_cna_basescore4.74.74.74.7
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_prHHH
cvss4_vuldb_uiNNN
cvss4_vuldb_vcLLL
cvss4_vuldb_viLLL
cvss4_vuldb_vaLLL
cvss4_vuldb_ePPP
cvss4_vuldb_atNNN
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss4_vuldb_bscore5.15.15.1
cvss4_vuldb_btscore2.02.02.0
cvss2_cna_auMM
cvss2_cna_ciPP
cvss2_cna_iiPP
cvss2_cna_aiPP
cvss2_cna_basescore5.85.8
cve_nvd_summaryesSe encontró una vulnerabilidad en los proyectos de código Faculty Management System 1.0. Ha sido calificada como crítica. Una función desconocida del archivo /admin/php/crud.php es afectada por esta vulnerabilidad. La manipulación del argumento fieldname conduce a la inyección de SQL. El ataque puede lanzarse de forma remota. La explotación ha sido divulgado al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-248948.Se encontró una vulnerabilidad en los proyectos de código Faculty Management System 1.0. Ha sido calificada como crítica. Una función desconocida del archivo /admin/php/crud.php es afectada por esta vulnerabilidad. La manipulación del argumento fieldname conduce a la inyección de SQL. El ataque puede lanzarse de forma remota. La explotación ha sido divulgado al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-248948.
cvss4_cna_avNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prHH
cvss4_cna_uiNN
cvss4_cna_vcLL
cvss4_cna_viLL
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_saNN
cvss4_cna_bscore5.15.1
cvss2_cna_avNN
cvss2_cna_acLL
cvss4_cna_siNN
euvd_idEUVD-2023-59280

Want to stay up to date on a daily basis?

Enable the mail alert feature now!