Revenue Collection System 1.0 SQL...

- AV AC AU C I A
发布: 2022-11-16
修订: 2025-04-13

Revenue Collection System version 1.0 suffers from an unauthenticated SQL injection vulnerability in step1.php that allows remote attackers to write a malicious PHP file to disk. The resulting file can then be accessed within the /rates/admin/DBbackup directory. This script will write the malicious PHP file to disk, issue a user-defined command, then retrieve the result of that command.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息