A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | Fanli2012 native-php-cms product_list.php sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2025-01-15T21:00:17.899Z
Updated: 2025-01-15T21:00:17.899Z
Reserved: 2025-01-15T12:43:49.092Z
Link: CVE-2025-0488
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-15T21:15:15.380
Modified: 2025-01-15T21:15:15.380
Link: CVE-2025-0488
Redhat
No data.