Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-29407
HistoryApr 18, 2023 - 12:00 a.m.

Campcodes Online Traffic Offense Management System SQL Injection Vulnerability (CNVD-2023-29407)

2023-04-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
sql injection
web-based system
vulnerability
validation
parameter
exploited
attackers
database
data theft

0.002 Low

EPSS

Percentile

52.2%

Campcodes Online Traffic Offense Management System is a web-based traffic offense management system. A SQL injection vulnerability exists in Campcodes Online Traffic Offense Management System v1.0. The vulnerability stems from the lack of validation of external input SQL statements in the parameter id of the file /classes/Master.php, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

0.002 Low

EPSS

Percentile

52.2%

Related for CNVD-2023-29407