6.8
CVSSv2

CVE-2008-3788

Published: 26/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b) _login.php.

Vulnerable Product Search on Vulmon Subscribe to Product

picturespro picturespro photo cart 3.9

Exploits

Author: ~!Dok_tOR!~ Date found: 180808 Product: PhotoCart Version: 39 возможно и более ранние версии Type: Photography Shopping Cart URL: wwwpicturesprocom Vulnerability Class: SQL Injection /[installdir]/searchphp Vuln code: PHP: if($_REQUEST['searchby'] == "q ...