Command School Student Management... CVE-2014-1636 CNNVD-201401-116

7.5 AV AC AU C I A
发布: 2014-01-22
修订: 2018-10-30

Command School Student Management System是一套基于Web的学生/学校管理系统。 Command School Student Management System 1.06.01中存在SQL注入漏洞。远程攻击者可借助在执行edit操作时‘id’参数发送至sw/目录下的多个脚本文件利用该漏洞执行任意SQL命令。脚本包括:(1)admin_school_names.php,(2)admin_subjects.php,(3)admin_grades.php,(4)admin_terms.php,(5)admin_school_years.php,(6)admin_sgrades.php,(7)admin_media_codes_1.php,(8)admin_infraction_codes.php,(9)admin_generations.php,(10)admin_relations.php,(11) admin_titles.php或(12)health_allergies.php。

0%
当前有12条漏洞利用/PoC
当前有1条受影响产品信息