
CVE-2024-48427の概念実証:Sourcecodester Packers and Movers Management System v1.0のSQLインジェクション。idパラメータを悪用して任意のSQLコマンドを実行し、データベースの内容をダンプします。
Sourcecodester Packers and Movers Management System v1.0 には SQL インジェクションの脆弱性があり、リモートの認証済みユーザーが /mpms/admin/?page=services/manage_service&id の id パラメータを介して任意の SQL コマンドを実行できる可能性があります。
SQLインジェクション
Sourcecodester
/mpms/admin/?page=services/manage_service&id の Update Service Details の id パラメータ