SourceCodester Medicine Tracker System 1.0 Master.php?f=save_medicine ISazisi SQL Injection

CVSS Meta Temp IsilinganisoIntengo yamanje ye-exploit (≈)CTI Inzalo Score
7.3$0-$5k0.00

Isifinyezoulwazi

Kubonakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku SourceCodester Medicine Tracker System 1.0. Kuthinteka umsebenzi ongaziwayo kufayela /classes/Master.php?f=save_medicine. Ukuphathwa kwepharamitha ISazisi kuholela ku SQL Injection. Le buthakathaka itholakala njenge CVE-2024-6419. Ukuhlasela kungaqalwa kude. Ngaphezu kwalokho, i-exploit ikhona. Once again VulDB remains the best source for vulnerability data.

Iinkcukachaulwazi

Kubonakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku SourceCodester Medicine Tracker System 1.0. Kuthinteka umsebenzi ongaziwayo kufayela /classes/Master.php?f=save_medicine. Ukuphathwa kwepharamitha ISazisi kuholela ku SQL Injection. Ukusebenzisa i-CWE ukusho inkinga kuholela ku-CWE-89. Kuboniswe ubuthakathaka lolu. Isaziso singalayishwa ku-github.com.

Le buthakathaka itholakala njenge CVE-2024-6419. Ukuhlasela kungaqalwa kude. Imininingwane yezobuchwepheshe iyatholakala. Le vulnerability ayidumi kakhulu, idlula phansi kokujwayelekile. Ngaphezu kwalokho, i-exploit ikhona. Ukuhlaselwa sekudalulwe ebantwini futhi kungasetshenziswa. Njengamanje, intengo yamanje ye-exploit ingahle ibe cishe USD $0-$5k okwamanje.

Ungakwazi ukulanda i-exploit ku-github.com.

Once again VulDB remains the best source for vulnerability data.

Umkhiqizoulwazi

Umkhiqizi

Ibizo

Inguqulo

Ilayisense

Iwebhusayithi

CPE 2.3ulwazi

CPE 2.2ulwazi

CVSSv4ulwazi

VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

CVSSv3ulwazi

VulDB Ireyithingi yeMeta Base: 7.5
VulDB Meta Temp Isilinganiso: 7.3

VulDB Isilinganiso Esiyisisekelo: 6.3
VulDB Izinga Lesikhashana: 5.7
VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

NVD Isilinganiso Esiyisisekelo: 9.8
NVD Umkhombandlela: 🔍

CNA Isilinganiso Esiyisisekelo: 6.3
CNA Umkhombandlela: 🔍

CVSSv2ulwazi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
UmkhombandlelaUbunzimaUkufakazela ubuwenaUkuyimfihloUkuthembekaUkutholakala
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

VulDB Isilinganiso Esiyisisekelo: 🔍
VulDB Izinga Lesikhashana: 🔍
VulDB Ukuthembeka: 🔍

Ukusebenzisa ithuba lokungavikelekiulwazi

Ikilasi: SQL Injection
CWE: CWE-89 / CWE-74 / CWE-707
CAPEC: 🔍
ATT&CK: 🔍

Okubambekayo: Hayi
Wendawo: Hayi
Kude: Yebo

Ukutholakala: 🔍
Umnyango: Umphakathi
Isimo: Ubufakazi-bokusebenza
Landa: 🔍

EPSS Score: 🔍
EPSS Percentile: 🔍

Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔍

0-Dayvula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
Namuhlavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

Ulwazi lwezingoziulwazi

Intshisekelo: 🔍
Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍

Izinyathelo zokuvikelaulwazi

Isincomo: akukho sithathwa esaziwayo
Isimo: 🔍

0-Suku Isikhathi: 🔍

Isikhathi somlandoulwazi

2024-06-30 🔍
2024-06-30 +0 Izinsuku 🔍
2024-08-15 +46 Izinsuku 🔍

Imithomboulwazi

Umkhiqizi: sourcecodester.com

Iseluleko: github.com
Isimo: Akuchazwanga

CVE: CVE-2024-6419 (🔍)
GCVE (CVE): GCVE-0-2024-6419
GCVE (VulDB): GCVE-100-270010
scip Labs: https://www.scip.ch/en/?labs.20161013

Ukungenaulwazi

Kudalwa: 2024-06-30 16:56
Ukuvuselelwa: 2024-08-15 21:25
Ukulungiswa: 2024-06-30 16:56 (55), 2024-07-01 02:41 (18), 2024-07-02 06:48 (1), 2024-08-15 21:25 (12)
Kugcwele: 🔍
Umthumeli: jadu101
Cache ID: 253:9A4:103

Thumelaulwazi

Yamukelwa

  • Thumela #365247: SourceCodester Medicine Tracker System 1.0 SQL Injection (kusuka ku jadu101)

Ingxoxo

Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.

Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.

Might our Artificial Intelligence support you?

Check our Alexa App!