vendor:
E-Ticaret V4
by:
Özkan Mustafa Akkuş (AkkuS)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: E-Ticaret V4
Affected Version From: v4.0
Affected Version To: v4.0
Patch Exists: YES
Related CWE: N/A
CPE: a:web-ofisi:e-ticaret_v4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: XAMPP for Linux
2018
WebOfisi E-Ticaret V4 – ‘urun’ SQL Injection
WebOfisi E-Ticaret V4 is a professional online shopping script with many features. Vulnerabilities have been discovered during penetration testing. The vulnerability is a SQL injection in the 'urun' parameter of the 'arama.html' page. The payloads used to exploit the vulnerability are boolean-based blind, error-based, stacked queries, and AND/OR time-based blind.
Mitigation:
Input validation should be used to prevent SQL injection attacks.