Anmei Century Hotel Broadband Operation System
cpe:2.3:a:amttgroup:hotel_broadband_operating_system:*:*:*:*:*:*:*
- 1.0
A SQL injection vulnerability has been identified in AMTT Hotel Broadband Operation System version 1.0. The issue resides in the file '/manager/card/cardmake_down.php', where manipulation of the 'id' parameter allows for SQL injection. This vulnerability can be exploited remotely, and an exploit is publicly available.
Exploitation of this vulnerability allows attackers to perform SQL injection, potentially leading to unauthorized access to the database and server privileges.
The vulnerability can be reproduced by sending a crafted HTTP GET request to '/manager/card/cardmake_down.php' with an injected 'id' parameter. The injection can be verified by using payloads that, for example, extract the database name.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.