Description
Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
KeopssGroup0day, Inc
References
www.exploit-db.com/exploits/49192 (ExploitDB-49192)
github.com/geraked/phpscript-sgh (Vendor Homepage)
www.vulncheck.com/...ript-sgh-time-based-blind-sql-injection (VulnCheck Advisory: Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection)