6.5
CVSSv2

CVE-2008-0911

Published: 22/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

iscripts multicart 2.0

Exploits

<html> <head> <style type="text/css"> <!-- style1{color: #CC0000} style2 { color: #000000; font-size: 12px;} style3 {color: #FF0000; font-weight: bold; font-size: 12px; } style4 {color: #FF0000; font-size: 10px;} --> </style> <title>MultiCart 20 Remote SQL Injection Vulnerbility</title> <script lan ...