CVE-2024-40498
CRITICALPuneethReddyHC Online Shopping <1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-40498. PoCs published by Dirac231.
AI-analyzed exploit summary The repository describes a SQL injection vulnerability in the `register.php` file of the `online-shopping-system-advanced 1.0` application. The unsanitized POST parameters `$address1` and `$address2` allow for SQL injection during the `VALUES()` statement evaluation.
Description
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php
Exploits (1)
The repository describes a SQL injection vulnerability in the `register.php` file of the `online-shopping-system-advanced 1.0` application. The unsanitized POST parameters `$address1` and `$address2` allow for SQL injection during the `VALUES()` statement evaluation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H