9.8
CVSSv3

CVE-2016-3694

Published: 15/02/2017 Updated: 23/02/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote malicious users to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.

Vulnerable Product Search on Vulmon Subscribe to Product

modified ecommerce shopsoftware 2.0.0.0

Exploits

# Title: Blind Injection modified eCommerce 2000 rev 9678 # Date: 16042016 # Category: webapps # Vendor Homepage: wwwmodified-shoporg/download # Software Link: wwwmodified-shoporg/forum/indexphp?action=downloads;sa=downfile&id=96 # Version: 2000 rev 9678 # Tested on: Apache/247, PHP Version 559, Linux # Exploit Au ...
modified eCommerce version 2000 revision 9678 suffers from a remote blind SQL injection vulnerability ...