CVE-2008-0681

Phpshop - SQL Injection

Title source: rule

Description

SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action.

Exploits (2)

exploitdb WORKING POC VERIFIED
by the redc0ders · textwebappsphp
https://www.exploit-db.com/exploits/5041
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/24108

Scores

EPSS 0.0033
EPSS Percentile 55.6%

Details

CWE
CWE-89
Status published
Products (1)
phpshop/phpshop 0.8.1
Published Feb 12, 2008
Tracked Since Feb 18, 2026