Fanli2012 Native-PHP-CMS SQL Injection Vulnerability in fladmin/cat_dodel.php

Vulnerability

A critical SQL injection vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises in the file fladmin/cat_dodel.php, where the input parameter 'id' is not properly sanitized. This lack of input validation allows attackers to inject malicious SQL commands, potentially leading to unauthorized data access or manipulation. The vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

To reproduce this vulnerability, send a request to fladmin/cat_dodel.php with a crafted 'id' parameter that includes SQL injection payloads. The lack of input filtering will allow the injected SQL to be executed, demonstrating the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
6.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.