7.5
CVSSv2

CVE-2008-2904

Published: 30/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote malicious users to execute arbitrary SQL commands via the cat parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmycart phpmycart

Exploits

###################### # #PHPMyCart Injection Vulnerability # ###################### # #Bug by: h0yt3r # ## ### ## # #Script suffers from a not correctly verified category id variable which is used in SQL Querys #An Attacker can easily get sensitive information from the database by #injecting unexpected SQL Querys # #We dont get any SQL Errors wh ...