PT-2007-4294 · Salescart · Salescart Shopping Cart

CVE-2007-2997

·

Publicado

2007-06-04

·

Atualizado

2024-08-07

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SalesCart Shopping Cart (affected versions not specified)
Description: The issue concerns SQL injection vulnerabilities in the cgi-bin/reorder2.asp file of SalesCart Shopping Cart, allowing remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. The vendor disputes this issue, stating it was reproducible on an old, out-of-date demo but not on the released product.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-2997

Produtos afetados

Salescart Shopping Cart