PT-2017-14920 · Php · Php Multivendor Ecommerce

Ihsan Sencan

·

Publicado

2017-12-13

·

Atualizado

2018-01-02

·

CVE-2017-17624

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP Multivendor Ecommerce version 1.0
Description The issue concerns SQL Injection, which can be exploited via the "single detail.php" page using the sid parameter, or through the "category.php" page using the searchcat or chid1 parameters.
Recommendations For PHP Multivendor Ecommerce version 1.0, consider restricting access to the single detail.php and category.php pages until a patch is available, and avoid using the sid, searchcat, and chid1 parameters in these pages to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17624

Produtos afetados

Php Multivendor Ecommerce