CVE-2011-4811

BST Bestshoppro - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CoBRa_21 · textwebappsphp
https://www.exploit-db.com/exploits/18063

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18063

Scores

EPSS 0.0025
EPSS Percentile 48.3%

Details

CWE
CWE-89
Status published
Products (1)
bst/bestshoppro
Published Dec 14, 2011
Tracked Since Feb 18, 2026