10
CVSSv2

CVE-2004-0300

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in Online Store Kit 3.0 allows remote malicious users to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ecommerce corporation online store kit 3.0_lite

ecommerce corporation online store kit 3.0_pro

ecommerce corporation online store kit 3.0_standard

Exploits

source: wwwsecurityfocuscom/bid/9676/info Multiple vulnerabilities have been identified in the software due to improper sanitization of user-supplied input Successful exploitation of these issues could allow an attacker to carry out cross-site scripting and SQL injection attacks via the 'id' parameter of 'morephp' script Online Store ...
source: wwwsecurityfocuscom/bid/9687/info It has been reported that Online Store Kit is prone to multiple SQL injection vulnerabilities These issues arise due to insufficient sanitation of user-supplied input via the URI As a result of this a malicious user may influence database queries in order to view or modify sensitive informa ...
source: wwwsecurityfocuscom/bid/9687/info It has been reported that Online Store Kit is prone to multiple SQL injection vulnerabilities These issues arise due to insufficient sanitation of user-supplied input via the URI As a result of this a malicious user may influence database queries in order to view or modify sensitive information ...
source: wwwsecurityfocuscom/bid/9687/info It has been reported that Online Store Kit is prone to multiple SQL injection vulnerabilities These issues arise due to insufficient sanitation of user-supplied input via the URI As a result of this a malicious user may influence database queries in order to view or modify sensitive informati ...