Описание
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
Ссылки
- ProductThird Party Advisory
- Product
- ExploitThird Party Advisory
- ProductThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.8 (исключая)
cpe:2.3:a:prestahome:blog:*:*:*:*:*:prestashop:*:*
EPSS
Процентиль: 99%
0.83038
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
EPSS
Процентиль: 99%
0.83038
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89