6.4
CVSSv2

CVE-2005-3914

Published: 30/11/2005 Updated: 08/03/2011
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 655
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote malicious users to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.

Vulnerable Product Search on Vulmon Subscribe to Product

affcommerce affcommerce 1.1.4

Exploits

source: wwwsecurityfocuscom/bid/15545/info AFFCommerce Shopping Cart is prone to multiple SQL injection vulnerabilities These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks AFFCommerce Shopping Cart 114 is reportedly affected ...
source: wwwsecurityfocuscom/bid/15545/info AFFCommerce Shopping Cart is prone to multiple SQL injection vulnerabilities These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks AFFCommerce Shopping Cart 114 is reportedly affected It ...
source: wwwsecurityfocuscom/bid/15545/info AFFCommerce Shopping Cart is prone to multiple SQL injection vulnerabilities These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks AFFCommerce Shopping Cart 114 is reportedly affected It is ...