Netartmedia PHP Mall SQL Injection Vulnerability

Vulnerability

Multiple SQL injection vulnerabilities have been identified in Netartmedia PHP Mall version 4.1. These vulnerabilities allow unauthenticated attackers to manipulate database queries by injecting unvalidated parameters. Exploitation can be achieved by sending time-based blind SQL payloads through the 'id' parameter in 'index.php' or the 'Email' parameter in 'loginaction.php', potentially leading to the extraction of sensitive database information.

Impact

Exploitation of these vulnerabilities allows for SQL injection, where attackers can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

The vulnerability can be reproduced by sending a request to 'index.php' with a crafted 'id' parameter that includes SQL injection payloads, such as those that exploit time-based blind SQL injection. Alternatively, the 'Email' parameter in 'loginaction.php' can be used to inject similar SQL payloads.

Added: Mar 12, 2026, 4:20 PM
Updated: Mar 12, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.