Kurniaramadhan E-Commerce-PHP SQL Injection Vulnerability

Vulnerability

A critical SQL injection vulnerability has been identified in Kurniaramadhan E-Commerce-PHP version 1.0, specifically within the file 'blog-details.php'. The vulnerability arises from the 'blog_id' parameter, allowing remote attackers to manipulate the argument and execute malicious SQL queries. This exploitation can lead to unauthorized access to sensitive data, including admin panel credentials, and potentially allow for the injection of malicious JavaScript into the application.

Impact

Exploitation of this vulnerability allows for SQL injection, which can be used to access and manipulate the application's database. This includes the potential to extract sensitive information such as admin credentials, which can then be used to access the admin panel and perform further actions, such as injecting malicious scripts that could be executed in the context of the user.

Reproduction

The vulnerability can be reproduced by sending a request to 'blog-details.php' with a crafted 'blog_id' parameter that includes SQL injection payloads. This can be done using a web browser or a tool like Burp Suite. Once the SQL injection is successful, the admin credentials can be extracted by exploiting the vulnerability further, such as by using 'union select' payloads to retrieve and decrypt the admin password.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.