Sourcecodester Cab Management System 1.0 的 manage_client.php 和 view_cab.php 中存在 SQL 注入漏洞,允许远程攻击者通过 id 参数执行任意 SQL 命令,从而导致未经授权的访问以及数据库中敏感数据的潜在泄露。
SQL 注入
Sourcecodester
https://www.sourcecodester.com/php/15180/cab-management-system-phpoop-free-source-code.html - 1.0
Sourcecodester Cab Management System v1.0 的 manage_client.php 和 view_cab.php 页面中的 id 参数存在 SQL 注入漏洞。