Joomla扩展 – phoca.cz – Phoca Cart 5.0.0–6.1.16 版本中,通过属性过滤器存在未认证的SQL注入漏洞 – Phoca Cart 公共商品页面中的 a[](属性)和 s[](规格)GET数组参数被直接拼接至SQL WHERE子句中,未使用参数化查询或转义处理。未认证的攻击者可通过这些参数注入任意SQL代码,从而利用基于时间的盲注技术实现完整数据库数据提取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| phoca.cz | Phoca Cart extension for Joomla | 5.0.0-6.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| phoca.cz | Phoca Cart extension for Joomla | 5.0.0-6.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet