7.5
CVSSv2

CVE-2008-2447

Published: 27/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote malicious users to execute arbitrary SQL commands via the cat parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mytipper zogo shop 1.15.5

mytipper zogo shop 1.16

Exploits

By Cr@zy_King / t4cs1zkr4L crazy_kinq@hotmailcouk / K0Lp4Lara dikkat : ) Zogo-shop 116 Beta 13 & e-107 Zozo-shop Plugins remote Sql Ä°nj Down : wwwmytippercom/downloadphp?view19 Sql : localhost/productsphp?cat=-1+union+select+database(),version(),3,4,5,6,user()/* Greatz : KnockOut / DrHack3r / Crackers_Child / Rm- ...