This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis →
Q1What is this vulnerability? (Essence + Consequences)
🚨 **Essence**: Time-based SQL Injection in `woof_author` parameter. 📉 **Consequences**: Full database compromise, data theft, or server takeover. Critical impact on confidentiality, integrity, and availability.
Q2Root Cause? (CWE/Flaw)
🛡️ **CWE-89**: Improper Neutralization of Special Elements used in an SQL Command. 💥 **Flaw**: Unsanitized user input in the `woof_author` parameter allows malicious SQL payloads.
Q3Who is affected? (Versions/Components)
🏢 **Vendor**: realmag777. 📦 **Product**: HUSKY – Products Filter Professional for WooCommerce. 📅 **Affected**: Version 1.3.6 and earlier. ⚠️ **Platform**: WordPress/WooCommerce sites.
Q4What can hackers do? (Privileges/Data)
🕵️ **Hackers Can**: Extract sensitive DB data, modify records, or execute administrative commands. 🔓 **Privileges**: High (CVSS 9.8). Can access user credentials, product info, and site config.
📜 **Public Exp?**: No specific PoC in data. 🔍 **References**: WordFence & WP Trac links available. 🌍 **Wild Exploitation**: Likely high given low complexity and remote nature.
Q7How to self-check? (Features/Scanning)
🔍 **Self-Check**: Scan for `woof_author` parameter in requests. 🛠️ **Tools**: Use SQLMap or WAF logs to detect time-based delays. 📊 **Indicator**: Look for unusual latency in filter responses.