The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_ln…
高危 CVSS 8.2
摘要
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
Lint 边界警告 (2)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://openises.sourceforge.net/ -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://sourceforge.net/projects/openises/files/latest/download
数据来源
- NVD DATABASE
原始链接
- http://openises.sourceforge.net/
- https://sourceforge.net/projects/openises/files/latest/download
- https://www.exploit-db.com/exploits/45645
- https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-sql-injection-via-nearby-php
时间线
- nvd_ingest NVD