A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Metrics
Affected Vendors & Products
References
History
Sun, 04 Jan 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Title | code-projects Online Product Reservation System POST Parameter edit.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-04T12:32:07.749Z
Reserved: 2026-01-03T16:01:54.337Z
Link: CVE-2026-0579
No data.
Status : Received
Published: 2026-01-04T13:15:42.427
Modified: 2026-01-04T13:15:42.427
Link: CVE-2026-0579
No data.
OpenCVE Enrichment
No data.