This is a technical writeup describing SQL injection vulnerabilities in PaulShop CMS <= 2017-03-25. It details the vulnerable parameters ('country' and 'weight') in the shipping cost page and provides example URLs for exploitation.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:PaulShop CMS <= 2017-03-25
No auth needed
Prerequisites:Access to the vulnerable PaulShop CMS instance