Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SourceCodester Bank Management System login.php sql injection
Vulnerability Description
A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Bank Management System SQL注入漏洞
Vulnerability Description
Bank Management System是一个银行管理系统。 SourceCodester Bank Management System 1.0 版本存在安全漏洞,该漏洞源于网站应用没有验证用户提交给服务器的数据的有效性。远程攻击者利用该漏洞可执行 sql 注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A