WebOfisi E-Ticaret 4.0 SQL Injection via urun Parameter
Vulnerability Description
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25210
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Özkan Mustafa Akkuş (AkkuS)
Affected Vendor
Web-Ofisi
View all reports →