CVE-2024-51211: openSIS Classic v9.1 – SQL Injection

CVE-2024-51211: openSIS Classic v9.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2024-51211: openSIS Classic v9.1 – SQL Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-51211: OpenSIS Classic v9.1 – SQL Injection

漏洞描述

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享