7.5
CVSSv2

CVE-2006-5957

Published: 17/11/2006 Updated: 17/05/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in INFINICART allow remote malicious users to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying "The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We have update our demo version and made sure all those vulnerabilities are fixed.

Vulnerable Product Search on Vulmon Subscribe to Product

infinicart infinicart

Exploits

source: wwwsecurityfocuscom/bid/21043/info Infinicart is prone to multiple input-validation vulnerabilities, including HTML-injection and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to compromise the application ...
source: wwwsecurityfocuscom/bid/21043/info Infinicart is prone to multiple input-validation vulnerabilities, including HTML-injection and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to compromise the applicati ...
source: wwwsecurityfocuscom/bid/21043/info Infinicart is prone to multiple input-validation vulnerabilities, including HTML-injection and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to compromise the application, ...