github.com
https://github.com/blindkey/cve_like/issues/13 CVE-2020-22211
CRITICALNuclei
74cms 74cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2020-22211 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
74cmsBrowse 74cms / 74cms | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICAL74cms - ajax_street.php 'key' SQL InjectionCVSS 9.8
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 'key' parameter of ajax_street.php in 74cms.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve202074cmssqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"
https://github.com/blindkey/cve_like/issues/13 https://nvd.nist.gov/vuln/detail/CVE-2020-22211 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-22211