PuneethReddyHC Online Shopping System Advanced
cpe:2.3:a:puneethreddyhc:online_shopping_system_advanced:*:*:*:*:*:*:*
- 1.0
A SQL injection vulnerability has been identified in the Online Shopping System Advanced version 1.0, specifically within the payment_success.php script. This vulnerability allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Exploitation of this issue enables the retrieval of sensitive database information by manipulating the user ID parameter.
Exploitation of this vulnerability allows for unauthorized access to the database, where attackers can inject and execute malicious SQL commands. This could lead to the disclosure of sensitive information, such as user credentials, which could be used to gain unauthorized access to the application or its database.
The vulnerability can be reproduced by sending a request to the payment_success.php script with a crafted 'cm' parameter that includes malicious SQL. This can be done using a tool like sqlmap, which can automate the injection of SQL payloads and exploit the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.