从这个网页截图中,可以获取到以下关于漏洞的关键信息: 1. 漏洞编号:#431782 2. 漏洞类型:SQL Injection 3. 漏洞描述: - SQL Injection vulnerability was identified in the infoAdd functionality of the BloodBank Management System version 1.0. - This vulnerability occurs during the creation of blood-related information, specifically when user inputs are not sanitized before being used in SQL queries. - The PoC shows that malicious SQL commands can be injected into the request body through parameters such as bg (blood group). This allows attackers to manipulate the backend query logic to extract or modify data. - Using blind logical injection techniques, the attack ensures successful exploitation by validating the logic embedded within the SQL query. 4. 漏洞来源: - https://gist.github.com/higordiego/25a103a1fe84c4db4530e68d2f998d11 5. 提交者:c4tr4ck (UID 75518) 6. 提交时间:2024年10月25日 22:15 7. 审核时间:2024年10月26日 15:44 8. 状态:已接受 9. VulDB Entry编号:281999 10. 积分:20