Back

CRITICAL

keerti1924 Online-Book-Store-Website HTTP POST Request shop.php sql injection

Published Mar 7, 2024

Description

A vulnerability classified as critical has been found in keerti1924 Online-Book-Store-Website 1.0. This affects an unknown part of the file /shop.php of the component HTTP POST Request Handler. The manipulation of the argument product_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256041 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 7, 2024
Updated Aug 12, 2024
Reserved Mar 7, 2024
CISA Vulnrichment
Updated Mar 8, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Mar 7, 2024
Updated Aug 12, 2024
Exploited since n/a
EUVD-2024-27226