7.5
CVSSv2

CVE-2007-6458

Published: 20/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote malicious users to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

my123tkshop e-commerce-suite 0.9.1

Exploits

By Michael Brooks Vulnerability:Sql Injection Software:123tkShop Homepage:sourceforgenet/projects/my123tkshop/ Affects Version 091 An attacker can gain Administrative rights with this authentication bypass exploit: 127001/123tkShop/shop/adminphp?admin=J3VuaW9uIHNlbGVjdCAncGFzc3dvcmQnLyogOnBhc3N3b3Jk The payload for the atta ...