Description
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
References
https://researchinthebin.org/posts/ofrs-sql-injection/
ExploitThird Party Advisory
https://researchinthebin.org/posts/ofrs-sql-injection/
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-06-14T01:15:08.153Z
3 years agoLast modified
2024-11-21T06:04:28.100Z
1 year ago