Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.04%
Published
Jan 20, 2011
Modified
Apr 28, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
Weaknesses (CWE)
Affected Products (43)
References (6)