Medium severity6.3NVD Advisory· Published Jul 14, 2022· Updated Jun 17, 2026
CVE-2017-20129
CVE-2017-20129
Description
A vulnerability was found in LogoStore. It has been classified as critical. Affected is an unknown function of the file /LogoStore/search.php. The manipulation of the argument query with the input test' UNION ALL SELECT CONCAT(CONCAT('qqkkq','VnPVWVaYxljWqGpLLbEIyPIHBjjjjASQTnaqfKaV'),'qvvpq'),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- oCrh&search= leads to sql injection. It is possible to launch the attack remotely.
Affected products
1- unspecified/LogoStorev5Range: n/a
Patches
Vulnerability mechanics
References
1- vuldb.comnvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.