Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-633w-j862-v7j8

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

EPSS

Процентиль: 86%
0.02785
Низкий

Связанные уязвимости

nvd
около 21 года назад

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

EPSS

Процентиль: 86%
0.02785
Низкий