Description
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2025-12-11: | Advisory disclosed |
| 2025-12-11: | VulDB entry created |
| 2025-12-11: | VulDB entry last update |
Credits
Rowan (VulDB User)
References
github.com/Rowantu/CVE/issues/7
vuldb.com/?id.335870 (VDB-335870 | Campcodes Retro Basketball Shoes Online Store admin_running.php sql injection)
vuldb.com/?ctiid.335870 (VDB-335870 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.703191 (Submit #703191 | Campcodes Retro Basketball Shoes Online Store V1.0 SQL Injection)
github.com/Rowantu/CVE/issues/7
www.campcodes.com/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.