孙一航

2 exploits Active since Nov 2024
CVE-2024-11059 WRITEUP MEDIUM WRITEUP
Project Worlds Free Download Online Shopping System - SQL Injection via success.php id Parameter
A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2024-11060 WRITEUP MEDIUM WRITEUP
Jinher Network Collaborative Management Platform 1.0 - SQL Injection
A vulnerability classified as critical has been found in Jinher Network Collaborative Management Platform 金和数字化智能办公平台 1.0. Affected is an unknown function of the file /C6/JHSoft.Web.AcceptAip/AcceptShow.aspx/. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3