vendor:
Online Shopping Alphaware
by:
Moaaz Taha (0xStorm)
7.5
CVSS
HIGH
Error-Based SQL injection
89
CWE
Product Name: Online Shopping Alphaware
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro 1909 (x64_86) + XAMPP 3.2.4
2020
Online Shopping Alphaware 1.0 – Error-Based SQL injection
This parameter "id" is vulnerable to Error-Based blind SQL injection in this path "/alphaware/details.php?id=431860" that leads to retrieve all databases.
Mitigation:
Implement proper input validation and parameterized queries to prevent SQL injection.