PT-2017-14920 · Php · Php Multivendor Ecommerce

Ihsan Sencan

·

Published

2017-12-13

·

Updated

2018-01-02

·

CVE-2017-17624

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP Multivendor Ecommerce version 1.0
Description The issue concerns SQL Injection, which can be exploited via the "single detail.php" page using the sid parameter, or through the "category.php" page using the searchcat or chid1 parameters.
Recommendations For PHP Multivendor Ecommerce version 1.0, consider restricting access to the single detail.php and category.php pages until a patch is available, and avoid using the sid, searchcat, and chid1 parameters in these pages to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17624

Affected Products

Php Multivendor Ecommerce