vendor:
E-ShopSystem
by:
Cyb3r-1sT
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: E-ShopSystem
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
E-ShopSystem Exploit
The E-ShopSystem script is vulnerable to SQL injection. An attacker can bypass the login page by injecting malicious SQL statements in the username and password fields.
Mitigation:
The vendor should release a patch or update to fix the SQL injection vulnerability. In the meantime, users should avoid using the affected version or implement additional security measures to mitigate the risk.