CVE-2021-41649
CRITICAL EXPLOITED NUCLEIonline-shopping-system-advanced - Unauthenticated SQL Injection via cat_id Parameter
Title source: llmExploitation Summary
CVE-2021-41649 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including MobiusBinary. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed writeup and SQLMap payloads for CVE-2021-41649, an SQL injection vulnerability in the 'online-shopping-system' affecting the 'cat_id' parameter in '/homeaction.php'. The payloads include boolean-based blind, error-based, time-based blind, and UNION query examples.
Description
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Exploits (1)
This repository provides a detailed writeup and SQLMap payloads for CVE-2021-41649, an SQL injection vulnerability in the 'online-shopping-system' affecting the 'cat_id' parameter in '/homeaction.php'. The payloads include boolean-based blind, error-based, time-based blind, and UNION query examples.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H