6.8
CVSSv2

CVE-2008-6986

Published: 19/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 up to and including 1.3.8a, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the products_id array parameter in a multiple_products_add_product action, a different vulnerability than CVE-2008-6985.

Vulnerable Product Search on Vulmon Subscribe to Product

zen-cart zen cart 1.3.2

zen-cart zen cart 1.3

zen-cart zen cart 1.3.8

zen-cart zen cart 1.3.8a

zen-cart zen cart 1.3.7

zen-cart zen cart 1.3.6

zen-cart zen cart 1.3.5

zen-cart zen cart 1.3.0.2