選單換圖效果,請啟用Active Scripting功能
南臺首頁 English
:::
訪客 未來學生 本校學生 教職同仁 畢業校友
:::
  南臺頭條新聞
  南臺影音新聞
  所有訊息
  重要公告
  行政公告
  校園活動
  專案計劃
  研討會資訊
  校內徵才
  校園職場實習
  工作機會
  國際證照
  南臺新生
  招生資訊
  南臺RSS新聞
  本月公告一覽
  停刊公告活動欄
  [公告系統登入]


【行政公告】 ::: [ 上一頁 ]
 
公 告 單位
圖資處網路系統組
訊 息 類 別 行政公告 行政公告 公 告 對 象 全體
公 告 主 題
【資安漏洞預警】威茗國際|旅行社管理系統 - SQL Injection
【Security Vulnerability Alert】Win Men International|Travel Agency Management System - SQL Injection
公 告 內 容
轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202608-00000008

[內容說明]
【威茗國際|旅行社管理系統 - SQL Injection】(CVE-2026-19425,CVSS:9.8) 威茗國際開發之旅行社管理系統存在SQL Injection漏洞,未經身分鑑別之遠端攻擊者可注入任意SQL指令讀取、修改及刪除資料庫內容。

[影響平台]
旅行社管理系統 2026 年 8 月安全性更新前的所有版本

[建議措施]
2026 年 8 月安全性更新

[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-11098-0fb4a-1.html

Forwarded from Taiwan Computer Emergency Response Team/Coordination Center Security Information Alert TWCERTCC-200-202608-00000008

[Description]
【Win Men International|Travel Agency Management System - SQL Injection】(CVE-2026-19425,CVSS:9.8) The Travel Agency Management System developed by Win Men International contains an SQL Injection vulnerability. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database contents.

[Affected Platforms]
All versions of the Travel Agency Management System prior to the August 2026 security update

[Recommended Measures]
August 2026 security update

[References]
1.https://www.twcert.org.tw/tw/cp-132-11098-0fb4a-1.html
相 關 訊 息
公 告 時 間
 2026/8/17   至 2027/2/17   
點 閱 次 數
88

:::
 
地址:71005 台南市永康區南台街一號 (開車訪客請由中正南路→正南一街→進入南臺科技大學) HyperLink