Exploit All Enthusiast ReviewPost PHP Pro 2.5 - 'showcat.php' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23646
Проверка EDB
  1. Пройдено
Автор
G00DB0Y
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2004-2175
Дата публикации
2004-02-04
Код:
source: https://www.securityfocus.com/bid/9574/info
 
It has been reported that ReviewPost PHP Pro may be prone to multiple SQL injection vulnerabilities that may allow an attacker to influence SQL query logic. This issue could be exploited to disclose sensitive information that may be used to gain unauthorized access. An attacker may pass malicious data via the 'product' parameter of 'showproduct.php' script and the 'cat' parameter of 'showcat.php' script.
 
Although unconfirmed, ReviewPost PHP Pro 2.5.1 and prior may be prone to these issues.

http://www.example.com/directory/showcat.php?cat=[query]
 
Источник
www.exploit-db.com