7.5
CVSSv2

CVE-2006-5962

Published: 17/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote malicious users to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

hpecs shopping cart hpecs shopping cart

Exploits

vendor site:hpenet/ product:hpecs shopping cart bug:injection sql risk:high login bypass : username: 'or''=' passwd: 'or''=' injection sql (post) : sitecom/search_listasp variables: Hpecs_Find=maingroup&searchstring='[sql] ( or just post your query in the search engine ) laurent gaffié & benjamin mossé ...