patch-1
Noam Rathaus 2021-06-02 09:39:35 +03:00
parent 2d52259f70
commit e3f42066bf
1 changed files with 1 additions and 1 deletions

View File

@ -3,7 +3,7 @@ id: CVE-2020-36112
info: info:
name: CSE Bookstore 1.0 SQL Injection name: CSE Bookstore 1.0 SQL Injection
author: geeknik author: geeknik
description: CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php. A successfull exploitation of this vulnerability will lead to an attacker dumping the entire database. description: CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database.
reference: | reference: |
- https://www.exploit-db.com/exploits/49314 - https://www.exploit-db.com/exploits/49314
- https://www.tenable.com/cve/CVE-2020-36112 - https://www.tenable.com/cve/CVE-2020-36112