First published: Tue Jan 07 2020(Updated: )
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpgurukul Dairy Farm Shop Management System Project Phpgurukul Dairy Farm Shop Management System | =1.0 | |
PHPGurukul Dairy Farm Shop Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-5307 is critical, with a severity value of 9.8.
The affected software for CVE-2020-5307 is Phpgurukul Dairy Farm Shop Management System 1.0.
CVE-2020-5307 manifests as a SQL injection vulnerability.
The username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php are vulnerable to SQL injection in CVE-2020-5307.
Yes, you can find more information about CVE-2020-5307 at the following references: [link1](https://cinzinga.github.io/CVE-2020-5307-5308/), [link2](https://www.exploit-db.com/exploits/47846).