vendor:
XOOPS Module Kshop
by:
ajann
7.5
CVSS
HIGH
Remote Blind SQL Injection
Not mentioned
CWE
Product Name: XOOPS Module Kshop
Affected Version From: 1.17 and below
Affected Version To: 1.17
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
Not mentioned
XOOPS Module Kshop <= 1.17 (id) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack on the XOOPS Module Kshop version 1.17 or below. By injecting a specially crafted payload into the 'id' parameter of the 'product_details.php' script, the attacker can extract sensitive information from the database, such as usernames and passwords.
Mitigation:
Upgrade to a patched version of XOOPS Module Kshop or apply appropriate security measures such as input validation and parameterized queries to prevent SQL injection attacks.