Vendor Homepageproduct
https://github.com/geraked/phpscript-sgh CVE-2020-36951
HIGH
Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection
Record summary
CVE-2020-36951 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
phpscript-sghBrowse geraked / phpscript-sgh | CVE List | 0.1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPhpscript-sgh 0.1.0 - Time Based Blind SQL InjectionExploitDB exploitby KeopssGroup0day_IncNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36951 ExploitDB-49192exploit
https://www.exploit-db.com/exploits/49192 VulnCheck Advisory: Phpscript-sgh 0.1.0 - Time Based Blind SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/phpscript-sgh-time-based-blind-sql-injection