Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-29406
HistoryApr 18, 2023 - 12:00 a.m.

Campcodes Online Traffic Offense Management System SQL Injection Vulnerability (CNVD-2023-29406)

2023-04-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
campcodes
online traffic offense management
sql injection
vulnerability
validation
external input
sql statements
parameter
password
login.php
attackers
illegal commands
sensitive data
database

0.002 Low

EPSS

Percentile

52.2%

Campcodes Online Traffic Offense Management System is a web-based traffic offense management system. A SQL injection vulnerability exists in Campcodes Online Traffic Offense Management System v1.0. The vulnerability stems from the lack of validation of external input SQL statements in the parameter password of the file /classes/Login.php, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

0.002 Low

EPSS

Percentile

52.2%

Related for CNVD-2023-29406