Record summary

CVE-2018-17110 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSimple POS 4.0.24 - 'columns[0][search][value]' SQL InjectionExploitDB exploitby Renos NikolaouNot analyzed1 file
ExploitDB

PoC details

References

2