S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-36112 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in CSE Bookstore affects v. 1.0.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-36112
9.8
CVSS

CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CSE Bookstore is an e-commerce platform developed for the Computer Science and Engineering students, teachers and professionals who are looking for books and digital assets related to their field. This web application provides a user-friendly interface with a wide range of categories, authors, publishers and languages. Customers can browse, search and purchase books, as well as add them to their cart and checkout securely.

However, the CSE Bookstore version 1.0 has recently been detected to have a serious vulnerability identified as CVE-2020-36112. This vulnerability is caused by a lack of proper input validation in the pubid parameter within the bookPerPub.php and cart.php pages. This vulnerability is a combination of time-based blind, boolean-based blind and OR error-based SQL injection that allows a malicious attacker to execute arbitrary SQL queries within the application's database.

If an attacker successfully exploits this vulnerability they can gain unauthorized access to sensitive information such as customer details, sales transactions, and other stored data. This can lead to malicious activities such as database manipulation, data leakage, identity theft, financial fraud, and many more.

In conclusion, the CSE Bookstore is an invaluable tool for computer science and engineering individuals, but this vulnerability presents a major threat to its security. Fortunately, security services such as s4e.io can help individuals understand and manage potential vulnerabilities before they even become an issue. By staying vigilant and taking proactive measures, users can ensure the safety of their digital assets and continue to enjoy the benefits of the CSE Bookstore without fear of exploitation.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against this vulnerability include:

  • Regularly updating and patching the application.
  • Implementing input sanitization techniques.
  • Using parameterized queries in place of dynamic queries.
  • Educating developers and security staff on secure coding practices.
  • Constantly monitoring the website's traffic and access logs to detect any suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.