vendor:
Online Shop Project
by:
Augkim
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Shop Project
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:online_shop_project_using_php_mysql
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache2
2020
Online Shop Project 1.0 – ‘p’ SQL Injection
The vulnerability exists due to an error in the 'p' parameter of '/shop/product.php' script, which can be exploited to inject or manipulate SQL queries. An attacker can send a specially crafted request to the vulnerable script and execute arbitrary SQL commands in application's database.
Mitigation:
Input validation should be used to prevent SQL injection attacks. The application should use parameterized queries (prepared statements) to prevent SQL injection attacks.