Showing 2 vulnerabilities on this page for Ashop Shopping Cart Software

Signals CISA KEV Ransomware Nuclei
Ashopsoftware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Ashop Shopping Cart Software Lastest SQL Injection via index.php

Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive database information.

CWE-89Mar 4, 2026
CVSS8.8v4.0EPSS0.237%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ashop Shopping Cart Software Lastest Latest SQL Injection via bannedcustomers.php

Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract sensitive database information.

CWE-89Feb 22, 2026
CVSS8.8v4.0EPSS0.263%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX