Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
keerti1924 Online-Book-Store-Website HTTP POST Request shop.php sql injection
Vulnerability Description
A vulnerability classified as critical has been found in keerti1924 Online-Book-Store-Website 1.0. This affects an unknown part of the file /shop.php of the component HTTP POST Request Handler. The manipulation of the argument product_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256041 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Online-Book-Store-Website SQL注入漏洞
Vulnerability Description
Online-Book-Store-Website是一个在线书店网站。 Online-Book-Store-Website 1.0 版本存在SQL注入漏洞,该漏洞源于 /shop.php 文件的 product_name 参数存在 SQL 注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A