漏洞描述 【漏洞对象】MallBuilder系统 【涉及版本】mallbuilder v7.3.4 【漏洞描述】 mallbuilderv7.3.4前台home.php页面存在cookie SQL注入漏洞,攻击者利用常用SQL注入工具获取数据库敏感信息。
相关漏洞推荐 POC CVE-2021-41649: PuneethReddyHC Online Shopping System homeaction.php SQL Injection POC CVE-2025-1743: Pichome 2.1.0 - Arbitrary File Read POC huawei-dg8045-home-gateway-password-leakage: Huawei DG8045 deviceinfo 信息泄漏漏洞 POC home-env-permission: User Home Directory and Shell Environment File Ownership & Permission POC huawei-home-gateway-hg659-fileread: Huawei Home Gateway Hg659 Fileread POC homeworks-illumination: HomeWorks Illumination Web Keypad POC esphome-dashboard: ESPHome Dashboard Exposure POC unauth-esphome: ESPHome Web Server access - Unauthenticated Access 统信UOS deepin-home-appstore-daemon 存在命令注入漏洞 Pichome /index.php 文件读取漏洞(CVE-2025-1743) Pichome /index.php 文件读取漏洞(CVE-2025-1743) Pichome 路径遍历漏洞 速达软件 多款产品 /login/home_jsontest.action 命令执行漏洞