关联漏洞
Description
CVE-2024-35468 | SQL injection
介绍
# CVE-2024-35468
#### Submitter: Kha Do
## Human Resource Management System 1.0
## Vulnerability
SQL injection
## Description
SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allow attackers to execute arbitrary SQL commands via the password parameters.
## Affected component
/hrm/index.php
## Impact
The attacker can use payload `'or'1'='1` login with administrator account without credentials.
## POC
Login with anonymous

Source code contain vulnerability

### Video
https://github.com/dovankha/SQLi_Login/assets/63991630/5ce70c62-86c7-4304-be04-1b8b53cf31c8
文件快照
[4.0K] /data/pocs/b5f552c8a075ec4f1e62a98aad51b0318fd5a7d6
└── [ 850] README.md
0 directories, 1 file
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →