SQL injection in the ID parameter of... CVE-2021-41609

7.5 AV AC AU C I A
发布: 2022-01-28
修订: 2024-11-21

SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息