vendor:
PhpIX 2012 Professional
by:
indoushka
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PhpIX 2012 Professional
Affected Version From: PhpIX 2012 Professional
Affected Version To: PhpIX 2012 Professional
Patch Exists: YES
Related CWE: CVE-2020-9079
CPE: a:allhandsmarketing:phpix_2012_professional
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
PhpIX 2012 Professional – ‘id’ SQL Injection
PhpIX 2012 Professional is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'id' parameter in the product_detail.php page. This can be exploited to bypass authentication, access, modify and delete data in the back-end database.
Mitigation:
The vendor has released a patch to address this vulnerability.