7.5
CVSSv2

CVE-2014-5104

Published: 28/07/2014 Updated: 29/07/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote malicious users to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to affiliate_show_banner.php, (3) country parameter in a process action to create_account.php, or (4) entry_country_id parameter in an edit action to admin/create_account.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ol-commerce project ol-commerce 2.1.1

Exploits

source: wwwsecurityfocuscom/bid/68719/info ol-commerce is prone to multiple SQL-injection vulnerabilities and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise th ...
source: wwwsecurityfocuscom/bid/68719/info ol-commerce is prone to multiple SQL-injection vulnerabilities and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromis ...
source: wwwsecurityfocuscom/bid/68719/info ol-commerce is prone to multiple SQL-injection vulnerabilities and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise ...
source: wwwsecurityfocuscom/bid/68719/info ol-commerce is prone to multiple SQL-injection vulnerabilities and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, comprom ...