关键漏洞信息 漏洞类型 SQL注入 软件 SLiMS 9.0.0 漏洞描述 The manual insertion with the parameter appears to be vulnerable to SQL injection attacks. The payload was submitted in manual insertion point 3. This payload injects a SQL sub-query that calls MySQL's function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. 漏洞状态 HIGH Vulnerability Payload示例 Reproduce和Exploit 提供了相关链接,用于复现和利用漏洞。 漏洞发现时间 3小时