Description
KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or error-based injection techniques.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Özkan Mustafa Akkuş (AkkuS)
References
www.exploit-db.com/exploits/44753 (ExploitDB-44753)
sitemakin.com (Official Product Homepage)
www.vulncheck.com/.../komseo-cart-sql-injection-via-edit-php (VulnCheck Advisory: KomSeo Cart 1.3 SQL Injection via edit.php)