7.5
CVSSv2

CVE-2010-1931

Published: 10/06/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 up to and including 4.3.9 allows remote malicious users to execute arbitrary SQL commands via the shipKey parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cubecart cubecart 4.3.4

cubecart cubecart 4.3.5

cubecart cubecart 4.3.6

cubecart cubecart 4.3.9

cubecart cubecart 4.3.7

cubecart cubecart 4.3.8

Exploits

SQL Injection in CubeCart PHP Free & Commercial Shopping Cart Application 1 *Advisory Information* Title: SQL Injection in CubeCart PHP Free & Commercial Shopping Cart Application Advisory Id: CORE-2010-0415 Advisory URL: [wwwcoresecuritycom/content/cubecart-php-shopping-cart-sql-injection] Date published: 2010-06-08 Date of la ...
Core Security Technologies Advisory - CubeCart PHP Free and Commercial Shopping Cart suffers from a remote SQL injection vulnerability ...