Product
An unauthenticated SQL injection vulnerability in the Online Clinic Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the Username argument in success/login.php.