Restaurant Order System SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in Restaurant Order System version 1.0. This vulnerability allows local attackers to access sensitive information through the payment.php file.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information stored in the application's database.
Reproduction
To reproduce this vulnerability, send a crafted GET request to the payment.php file. Include a SQL injection payload that exploits the application's SQL query handling. The payload should be designed to extract data from the database, such as using a UNION SELECT injection to retrieve information from other tables.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
