6.8
CVSSv2

CVE-2008-6985

Published: 19/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 up to and including 1.3.8a, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.

Vulnerable Product Search on Vulmon Subscribe to Product

zen-cart zen cart 1.2.4.1

zen-cart zen cart 1.2.1d

zen-cart zen cart 1.3

zen-cart zen cart 1.2.1_patch1

zen-cart zen cart 1.2.4d

zen-cart zen cart 1.2.3d

zen-cart zen cart 1.3.5

zen-cart zen cart 1.3.8a

zen-cart zen cart 1.2.2d

zen-cart zen cart 1.2.0d

zen-cart zen cart 1.3.7

zen-cart zen cart 1.3.6

zen-cart zen cart 1.2.6d

zen-cart zen cart 1.2.5d

zen-cart zen cart 1.3.8

zen-cart zen cart 1.3.2

Exploits

Zen Cart SQL Injection Vendor: Zen Ventures, LLC Product: Zen Cart Version: <= 138a Website: wwwzen-cartcom BID: 31023 CVE: CVE-2008-6985 OSVDB: 48346 SECUNIA: 31758 PACKETSTORM: 69640 Description: Zen Cart is a full featured open source ecommerce web application written in php that allows users to build, run and promote their ...