Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques. | |
| Title | Victor CMS 1.0 - 'post' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-03T22:01:43.785Z
Updated: 2026-02-03T22:01:43.785Z
Reserved: 2026-02-01T13:16:06.485Z
Link: CVE-2020-37076
No data.
Status : Received
Published: 2026-02-03T22:16:23.133
Modified: 2026-02-03T22:16:23.133
Link: CVE-2020-37076
No data.