CVE-2020-25362
HIGHOnline Shopping Alphaware 1.0 - SQL Injection via id Parameter in details.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25362. PoCs published by Moaaz Taha.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Online Shopping Alphaware 1.0 by using sqlmap to retrieve database information via the 'id' parameter in details.php. It relies on an external tool (sqlmap) rather than providing standalone exploit code.
Description
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Online Shopping Alphaware 1.0 by using sqlmap to retrieve database information via the 'id' parameter in details.php. It relies on an external tool (sqlmap) rather than providing standalone exploit code.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N