HTTP: phpMyShop SQL Injection Vulnerability
This signature detects attempts to exploit a SQL injection vulnerability in the phpMyShop package. phpMyShop 1.00 and earlier versions are vulnerable. Attackers can submit a maliciously crafted URL to the Web server to bypass authorization.
Extended Description
phpMyShop, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries. This vulnerability was reported to exist in the compte.php script file. A remote attacker can exploit this vulnerability to bypass the phpMyShop authentication/registration process.
Affected Products
Julien_desaunay phpmyshop
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Julien_desaunay