漏洞描述 【漏洞对象】天柏在线培训系统 【漏洞描述】天柏在线培训系统的/web/Search_List.aspx文件search参数存在SQL注入,可造成信息数据泄露,攻击者可利用该漏洞执行SQL指令,甚至入侵服务器。
相关漏洞推荐 NodeBB /api/v3/search/categories SQL 注入漏洞(CVE-2025-50979) Progress Chef Automate /api/v0/compliance/profiles/search SQL 注入漏洞(CVE-2025-8868) Whoogle search 代码执行漏洞(CVE-2024-53305) ZZZCMS /search/ 代码执行漏洞(CVE-2019-9041) 汉王e脸通综合管理平台 searchVisitReason.do 存在SQL注入漏洞 POC CVE-2010-1340: Joomla! Component com_jresearch - 'Controller' Local File Inclusion POC CVE-2015-3337: Elasticsearch - Local File Inclusion POC CVE-2016-1000130: WordPress e-search <=1.0 - Cross-Site Scripting POC CVE-2016-1000131: WordPress e-search <=1.0 - Cross-Site Scripting POC CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure POC CVE-2023-30192: PrestaShop 'possearchproducts' <= 1.7 - SQL Injection POC CVE-2015-3337: Elasticsearch File Read POC CVE-2015-5531: Elasticsearch CVE-2015-5531