Description
PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the 'id' parameter to potentially extract or modify database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
indoushka
References
www.exploit-db.com/exploits/48138 (ExploitDB-48138)
www.allhandsmarketing.com/ (Vendor Homepage)
www.pcollectionnecktie.com/sandbox/ (Demonstration Website)
www.vulncheck.com/...ies/phpix-professional-id-sql-injection (VulnCheck Advisory: PhpIX 2012 Professional - 'id' SQL Injection)