SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
References
Link | Resource |
---|---|
https://github.com/Future-Depth/IMS/issues/1 | Exploit Issue Tracking Vendor Advisory |
https://github.com/Future-Depth/IMS/issues/1 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Future-Depth/IMS/issues/1 - Exploit, Issue Tracking, Vendor Advisory |
Information
Published : 2023-02-08 19:15
Updated : 2024-11-21 07:29
NVD link : CVE-2022-45526
Mitre link : CVE-2022-45526
CVE.ORG link : CVE-2022-45526
JSON object : View
Products Affected
institutional_management_website_project
- institutional_management_website
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')