Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgxj-6h4c-hpvg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

EPSS

Процентиль: 93%
0.10359
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

EPSS

Процентиль: 93%
0.10359
Средний

Дефекты

CWE-89