Description
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract sensitive database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Doğukan Karaciğer
References
www.exploit-db.com/exploits/46681 (ExploitDB-46681)
www.vulncheck.com/...st-sql-injection-via-bannedcustomersphp (VulnCheck Advisory: Ashop Shopping Cart Software Lastest Latest SQL Injection via bannedcustomers.php)