header-logo
Suggest Exploit
vendor:
PhpIX 2012 Professional
by:
indoushka
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PhpIX 2012 Professional
Affected Version From: PhpIX 2012 Professional
Affected Version To: PhpIX 2012 Professional
Patch Exists: YES
Related CWE: CVE-2020-9079
CPE: a:allhandsmarketing:phpix_2012_professional
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows 10
2020

PhpIX 2012 Professional – ‘id’ SQL Injection

PhpIX 2012 Professional is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'id' parameter in the product_detail.php page. This can be exploited to bypass authentication, access, modify and delete data in the back-end database.

Mitigation:

The vendor has released a patch to address this vulnerability.
Source

Exploit-DB raw data:

# Title: PhpIX 2012 Professional - 'id' SQL Injection
# Date: 2020-02-26
# Author: indoushka
# Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit)
# Vendor    : http://www.allhandsmarketing.com/

# poc :


[+] Dorking İn Google Or Other Search Enggine.

[+] /product_detail.php?id=448578 <====| inject here

[+] http://www.pcollectionnecktie.com/sandbox/ <====| Login


Greetings to :=========================================================================================================================
                                                                                                                                      |
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm*                                            |        
                                                                                                                                      |
=======================================================================================================================================