Bylancer Quicklancer 2.4 G - SQL Injection
A SQL injection vulnerability exists in the Quicklancer 2.4, GET parameter 'range2', that has time-based blind SQL injection and a boolean-based blind SQL injection, which can be exploited remotely by unauthenticated attacker to execute arbitrary SQL queries in the database.
quicklancerPoC 已收录
CVSS7.3EPSS 81.2%