Record summary

CVE-2020-36951 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBPhpscript-sgh 0.1.0 - Time Based Blind SQL InjectionExploitDB exploitby KeopssGroup0day_IncNot analyzed1 file
ExploitDB

PoC details

References

4