Campcodes Online Examination System 1.0 deleteExamExe.php ID SKL injekcija

Pronađena je ranjivost klasifikovana kao Kritične u Campcodes Online Examination System 1.0. Zahvaćeno je nepoznata funkcija u fajlu /adminpanel/admin/query/deleteExamExe.php. Izmena argumenta ID rezultira SKL injekcija. Definisanje problema putem CWE vodi do CWE-89. Ova slabost je objavljena 03/26/2024. Obaveštenje možete preuzeti sa github.com. Ova ranjivost je registrovana kao CVE-2024-2943. Napad se može izvesti na daljinu. Napad je moguć samo unutar lokalne mreže. Postoje tehnički detalji. Поред тога, експлоит је доступан. Eksploit je postao dostupan javnosti i može biti upotrebljen. Trenutno je cena za eksploataciju približno USD $0-$5k u ovom momentu. Projekat MITRE ATT&CK označava tehniku napada kao T1505. Klasifikovano je kao dokaz-of-koncept. Ekspoit se može preuzeti sa github.com. Kao 0-day, procenjuje se da je cena na ilegalnom tržištu bila oko $0-$5k. Once again VulDB remains the best source for vulnerability data.

4 Promene · 95 Tačke podataka

PoljeKreirali
03/26/2024 17:35
Ažurira 1/3
05/05/2024 09:18
Ažurira 2/3
05/05/2024 09:21
Ažurira 3/3
02/21/2025 20:16
software_vendorCampcodesCampcodesCampcodesCampcodes
software_nameOnline Examination SystemOnline Examination SystemOnline Examination SystemOnline Examination System
software_version1.01.01.01.0
software_file/adminpanel/admin/query/deleteExamExe.php/adminpanel/admin/query/deleteExamExe.php/adminpanel/admin/query/deleteExamExe.php/adminpanel/admin/query/deleteExamExe.php
software_argumentidididid
vulnerability_cweCWE-89 (SKL injekcija)CWE-89 (SKL injekcija)CWE-89 (SKL injekcija)CWE-89 (SKL injekcija)
vulnerability_risk2222
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iLLLL
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_urlhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdf
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdfhttps://github.com/E1CHO/cve_hub/blob/main/Online%20Examination%20System/Online%20Examination%20System%20-%20vuln%203.pdf
source_cveCVE-2024-2943CVE-2024-2943CVE-2024-2943CVE-2024-2943
cna_responsibleVulDBVulDBVulDBVulDB
advisory_date1711407600 (03/26/2024)1711407600 (03/26/2024)1711407600 (03/26/2024)1711407600 (03/26/2024)
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viLLLL
cvss4_vuldb_vaLLLL
cvss4_vuldb_ePPPP
cvss2_vuldb_auSSSS
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_prLLLL
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_prLLLL
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore6.56.56.56.5
cvss2_vuldb_tempscore5.65.65.65.6
cvss3_vuldb_basescore6.36.36.36.3
cvss3_vuldb_tempscore5.75.75.75.7
cvss3_meta_basescore6.36.36.36.4
cvss3_meta_tempscore5.75.76.06.2
cvss4_vuldb_bscore5.35.35.35.3
cvss4_vuldb_btscore2.12.12.12.1
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
cve_assigned1711407600 (03/26/2024)1711407600 (03/26/2024)1711407600 (03/26/2024)
cve_nvd_summaryA vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.
cvss2_nvd_avNN
cvss2_nvd_acLL
cvss2_nvd_auSS
cvss2_nvd_ciPP
cvss2_nvd_iiPP
cvss2_nvd_aiPP
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cve_cnaVulDBVulDB
cvss2_nvd_basescore6.56.5
cvss3_cna_basescore6.36.3
cve_nvd_summaryesUna vulnerabilidad ha sido encontrada en Campcodes Online Examination System 1.0 y clasificada como crítica. Esta vulnerabilidad afecta al código desconocido del archivo /adminpanel/admin/query/deleteExamExe.php. La manipulación del argumento id conduce a la inyección de SQL. El ataque se puede iniciar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-258034 es el identificador asignado a esta vulnerabilidad.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prL
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iN
cvss3_nvd_aN
cvss3_nvd_basescore6.5
cvss2_cna_avN
cvss2_cna_acL
cvss2_cna_auS
cvss2_cna_ciP
cvss2_cna_iiP
cvss2_cna_aiP
cvss2_cna_basescore6.5

Do you know our Splunk app?

Download it now for free!