CVE-2010-4845

MH Products Projekt Shop - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4845. PoCs published by DeadLy DeMon.

AI-analyzed exploit summary This is a writeup describing SQL injection vulnerabilities in Projekt Shop's details.php and search functionality. It provides target URLs with injection points but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by DeadLy DeMon · textwebappsphp
https://www.exploit-db.com/exploits/15773

This is a writeup describing SQL injection vulnerabilities in Projekt Shop's details.php and search functionality. It provides target URLs with injection points but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Projekt Shop (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64205
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42711
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45506
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15773

Scores

EPSS 0.0101
EPSS Percentile 58.7%

Details

CWE
CWE-89
Status published
Products (1)
mhproducts/projekt_shop
Published Sep 27, 2011
Tracked Since Feb 18, 2026