code-projects E-Commerce Website sql injection

CVE Details

Basic Information

Title code-projects E-Commerce Website sql injection
Type cve
Published 2023-12-25T23:00:06.432Z
Modified 2024-08-26T14:52:32.045Z

Product Information

Vendor code-projects
Product E-Commerce Website
Version 1.0

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Analysis

AI Description A SQL injection vulnerability was discovered in the code-projects E-Commerce Website version 1.0. This vulnerability allows remote attackers to inject SQL code via the ‘prod_id’ parameter in product_details.php, potentially leading to data extraction or modification.
AI Severity Medium
AI Vendor code-projects
AI Product E-Commerce Website
AI Version 1.0

Affected Products

  • code-projects E-Commerce Website 1.0

Additional Information

CWE List CWE-89
Source VulDB

Description

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file product_details.php?prod_id=11. The manipulation of the argument prod_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249001 was assigned to this vulnerability.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.