Ashop Shopping Cart Software Time-Based Blind SQL Injection Vulnerability

Vulnerability

A time-based blind SQL injection vulnerability has been identified in Ashop Shopping Cart Software. This vulnerability allows attackers to manipulate database queries by sending crafted SQL payloads through the blacklistitemid parameter in POST requests to the admin/bannedcustomers.php endpoint. Exploitation of this vulnerability enables the extraction of sensitive database information by using SLEEP functions to create a time delay, indicating successful payload execution.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where attackers can manipulate SQL queries and potentially extract sensitive information from the database.

Reproduction

To reproduce this vulnerability, send a POST request to the admin/bannedcustomers.php endpoint with the blacklistitemid parameter. Include a crafted SQL payload that utilizes the SLEEP function to create a delay in the response, indicating successful exploitation.

Added: Feb 22, 2026, 2:21 PM
Updated: Feb 22, 2026, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.0
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.