vendor:
Online shopping system advanced
by:
Majid kalantari
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online shopping system advanced
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE:
CPE: Not available
Platforms Tested: Windows 10
2020
Online shopping system advanced 1.0 – ‘p’ SQL Injection
The 'p' parameter in the product.php file of the Online shopping system advanced 1.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to retrieve sensitive information from the database.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and parameterized queries to prevent SQL Injection attacks.