7.5
CVSSv2

CVE-2007-3323

Published: 21/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote malicious users to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.

Vulnerable Product Search on Vulmon Subscribe to Product

comersus open technologies comersus cart 7.07

Exploits

source: wwwsecurityfocuscom/bid/24562/info Comersus Cart is affected by multiple input validation vulnerabilities A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database The attacker may also leverage this issue to execute arbitrary code i ...