Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Victor Cms Project
Victor Cms Project victor Cms |
|
| CPEs | cpe:2.3:a:victor_cms_project:victor_cms:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Victor Cms Project
Victor Cms Project victor Cms |
Wed, 04 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Victoralagwu
Victoralagwu cmssite |
|
| Vendors & Products |
Victoralagwu
Victoralagwu cmssite |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques. | |
| Title | Victor CMS 1.0 - 'post' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-03T22:01:43.785Z
Updated: 2026-02-04T16:20:31.216Z
Reserved: 2026-02-01T13:16:06.485Z
Link: CVE-2020-37076
Updated: 2026-02-04T16:20:15.376Z
Status : Analyzed
Published: 2026-02-03T22:16:23.133
Modified: 2026-02-10T14:53:04.593
Link: CVE-2020-37076
No data.