CVE-2020-19108: SQL Injection
Published May 5, 2021
·Updated
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
Affected Software
1 affected component
Projectworlds Online Book Store Project In Php=1.0
Event History
May 5, 2021
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-19108.
2
What is the severity of CVE-2020-19108?
The severity of CVE-2020-19108 is critical.
3
How can a remote malicious user exploit CVE-2020-19108?
A remote malicious user can exploit CVE-2020-19108 through a SQL Injection vulnerability by manipulating the 'pubid' parameter in 'bookPerPub.php'.
4
What can a remote malicious user do if they successfully exploit CVE-2020-19108?
If a remote malicious user successfully exploits CVE-2020-19108, they can execute arbitrary code.
5
Is there a fix available for CVE-2020-19108?
Yes, it is recommended to apply the latest security patches or updates provided by the vendor to fix CVE-2020-19108.