SQL Injection Vulnerability in E-commerce MLM Software by E-commerce Vendor
CVE-2017-17610
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 13 December 2017
What is CVE-2017-17610?
E-commerce MLM Software version 1.0 is susceptible to SQL Injection vulnerabilities through the 'pid' parameter in service_detail.php, the 'eventid' parameter in event_detail.php, and the 'newid' parameter in news_detail.php. Exploiting these weaknesses could allow an attacker to execute arbitrary SQL code, potentially leading to unauthorized access to sensitive data and compromising the integrity of the database.
