S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 22, 2024

CVE-2023-40749 Scanner

CVE-2023-40749 Scanner - SQL Injection vulnerability in PHPJabbers Food Delivery Script

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-40749
9.8
CVSS

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

PHPJabbers Food Delivery Script is a web-based software widely used by food businesses, such as restaurants and cafes, to facilitate online ordering and delivery services. Developed by PHPJabbers, it offers businesses an effective way to manage orders, track deliveries, and communicate with customers. The script allows integration with various payment gateways, enhancing the user experience and business efficiency. Businesses use this script to streamline operations, improve customer service, and boost overall sales. It is popular due to its user-friendly interface, customizable features, and compatibility with different web hosting services.

SQL Injection is one of the most critical vulnerabilities that affects web applications, including PHPJabbers Food Delivery Script. This vulnerability occurs when an attacker is able to manipulate a database query by injecting arbitrary SQL code into it. Such vulnerabilities can allow attackers to perform unauthorized actions like data retrieval, modification, and even deletion within the affected database. SQL Injection vulnerabilities usually occur due to insufficient input validation, providing attackers the opportunity to exploit vulnerable query parameters. The consequences of such an attack can be severe, compromising data integrity, confidentiality, and availability.

The SQL Injection in PHPJabbers Food Delivery Script v3.0 is located at the "column" parameter in the index.php file of the application. An attacker can exploit this vulnerable parameter by crafting malicious SQL statements to manipulate or extract data from the database. The vulnerability can be triggered by sending a specially crafted POST request to the application, bypassing standard SQL checks. This allows the execution of arbitrary SQL commands, endangering the application's database. By exploiting this vulnerability, an attacker could potentially access sensitive data or tamper with critical aspects of the application.

If exploited, SQL Injection in PHPJabbers Food Delivery Script can lead to unauthorized access to sensitive data, such as customer information and order details. This can result in data breaches, affecting user privacy and business reputation. In severe cases, attackers may alter or destroy database entries, compromising the integrity and availability of services. Financial losses may occur due to the disruption of services or theft of data. Additionally, SQL Injection can serve as an entry point for further attacks, making it a critical vulnerability that needs immediate attention.

REFERENCES

Solution Advice
  • Sanitize and validate all inputs to ensure they do not contain SQL syntax before processing.
  • Use prepared statements and parameterized queries to prevent injection vulnerabilities.
  • Implement robust error handling to obscure SQL errors from end users.
  • Regularly review and update code to patch vulnerabilities and improve security posture.
  • Employ a web application firewall (WAF) to detect and block SQL injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.