github.com
https://github.com/blindkey/cve_like/issues/12 CVE-2020-22209
CRITICALNuclei
74cms - ajax_common.php SQL Injection
Record summary
CVE-2020-22209 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICAL74cms - ajax_common.php SQL InjectionCVSS 9.8
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the underlying database.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_common.php file.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve202074cmssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"
https://github.com/blindkey/cve_like/issues/12 https://nvd.nist.gov/vuln/detail/CVE-2020-22209 https://github.com/20142995/sectool https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-22209