jimit105 Project-Online-Shopping-Website Product Inventory /delete.php product_code SQL ଇଞ୍ଜେକ୍ସନ

Dogoggorri kan akka ଜଟିଳ jedhamuun ramadame jimit105 Project-Online-Shopping-Website ଯେପର୍ଯ୍ୟନ୍ତ 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64 keessatti argameera. Miidhamni argame is hojii hin beekamne faayilii /delete.php keessa kutaa Product Inventory Handler keessa. Wanti jijjiirame irratti product_code gara SQL ଇଞ୍ଜେକ୍ସନ geessa. Rakkoo ibsuuf CWE yoo fayyadamte gara CWE-89 si geessa. Odeeffannoon kun yeroo 10/11/2025 maxxanfameera. Odeeffannoon kun buufachuuf github.com irratti argama. Dogoggorri kun CVE-2025-11628 jedhamee waamama. Weerara fageenya irraa jalqabuu ni danda'ama. Ibsa teeknikaa ni jira. Waan dabalataa ta’een, meeshaa balaa kana fayyadamuuf ni jira. Qorannoo miidhaa (exploit) uummataaf ifa taasifameera, kanaafis fayyadamuu ni danda'ama. Ammas, gatii exploit might be approx. USD $0-$5k yeroo ammaa irratti argamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ ta’uu isaa ibsameera. Exploit github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatiin isaa daldala dhoksaa keessatti $0-$5k akka ta'e tilmaamameera. Odeeffannoon kun tajaajila rolling release fayyadama, kanaafis tamsaasa itti fufinsa qabu ni kenna. Kanaaf, odeeffannoon gosa version jijjiirame yookaan kan miidhamte hin jiru. If you want to get best quality of vulnerability data, you may have to visit VulDB.

4 ଆଡାପ୍ଟେସନ୍ · 96 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
10/11/2025 03:47 PM
ଅଦ୍ୟତନ 1/3
10/12/2025 07:20 AM
ଅଦ୍ୟତନ 2/3
10/12/2025 08:19 AM
ଅଦ୍ୟତନ 3/3
10/13/2025 08:37 PM
cvss4_vuldb_ePPPP
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore5.85.85.85.8
cvss2_vuldb_tempscore5.05.05.05.0
cvss3_vuldb_basescore4.74.74.74.7
cvss3_vuldb_tempscore4.34.34.34.3
cvss3_meta_basescore4.74.74.74.7
cvss3_meta_tempscore4.34.54.54.5
cvss4_vuldb_bscore5.15.15.15.1
cvss4_vuldb_btscore2.02.02.02.0
advisory_date1760133600 (10/11/2025)1760133600 (10/11/2025)1760133600 (10/11/2025)1760133600 (10/11/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
software_vendorjimit105jimit105jimit105jimit105
software_nameProject-Online-Shopping-WebsiteProject-Online-Shopping-WebsiteProject-Online-Shopping-WebsiteProject-Online-Shopping-Website
software_version<=7d892f442bd8a96dd242dbe2b9bd5ed641e13e64<=7d892f442bd8a96dd242dbe2b9bd5ed641e13e64<=7d892f442bd8a96dd242dbe2b9bd5ed641e13e64<=7d892f442bd8a96dd242dbe2b9bd5ed641e13e64
software_rollingrelease1111
software_componentProduct Inventory HandlerProduct Inventory HandlerProduct Inventory HandlerProduct Inventory Handler
software_file/delete.php/delete.php/delete.php/delete.php
software_argumentproduct_codeproduct_codeproduct_codeproduct_code
vulnerability_cweCWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)CWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)CWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)CWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)
vulnerability_risk2222
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_prHHHH
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iLLLL
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_urlhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docx
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docxhttps://github.com/mhszed/Report/blob/main/Project-Online-Shopping-Website%20exit%20sql.docx
source_cveCVE-2025-11628CVE-2025-11628CVE-2025-11628CVE-2025-11628
cna_responsibleVulDBVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
software_typeProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management Software
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_auMMMM
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_prHHHH
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viLLLL
cvss4_vuldb_vaLLLL
cve_nvd_summaryA flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
cvss4_cna_avNNN
cvss4_cna_acLLL
cvss4_cna_atNNN
cvss4_cna_prHHH
cvss4_cna_uiNNN
cvss4_cna_vcLLL
cvss4_cna_viLLL
cvss4_cna_vaLLL
cvss4_cna_scNNN
cvss4_cna_siNNN
cvss4_cna_saNNN
cvss4_cna_bscore5.15.15.1
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prHHH
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iLLL
cvss3_cna_aLLL
cvss3_cna_basescore4.74.74.7
cvss2_cna_avNNN
cvss2_cna_acLLL
cvss2_cna_auMMM
cvss2_cna_ciPPP
cvss2_cna_iiPPP
cvss2_cna_aiPPP
cvss2_cna_basescore5.85.85.8
euvd_idEUVD-2025-33883EUVD-2025-33883
cnnvd_idCNNVD-202510-1618
cnnvd_nameProject-Online-Shopping-Website SQL注入漏洞
cnnvd_hazardlevel3
cnnvd_create2025-10-13
cnnvd_publish2025-10-12
cnnvd_update2025-10-13

Do you know our Splunk app?

Download it now for free!