Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-71115
HistoryFeb 28, 2022 - 12:00 a.m.

Tongda2000 SQL Injection Vulnerability (CNVD-2022-71115)

2022-02-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
tongda2000
sql injection
change_box.php
delete_str parameter
china
cnvd-2022-71115

EPSS

0.002

Percentile

53.1%

Tongda2000 is a web-based intelligent office system from Tongda, China. a SQL injection vulnerability exists in Tongda2000 v11.10, which stems from the product’s failure to effectively filter the special characters in the DELETE_STR parameter data in the change_box.php file. An attacker could use this vulnerability to execute malicious SQL.

EPSS

0.002

Percentile

53.1%

Related for CNVD-2022-71115