6.4
CVSSv2

CVE-2007-5261

Published: 06/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote malicious users to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

iscripts multicart 1.0

Exploits

# Indonesian Newhack Security Advisory # ------------------------------------ # MultiCart 10 Remote Blind SQL Injection # Waktu : Sep 30 2007 02:00AM # Software : MultiCart 10 # Vendor : wwwiscriptscom/multicart/ # Ditemukan oleh : k1tk4t | newhackorg # Lokasi : Indonesia # # ---- # /categorydetailphp?catid=[BLIND ...