PT-2005-3382 · Naxtor · Naxtor Shopping Cart

John Cobb

·

Publicado

2005-08-05

·

Atualizado

2017-07-11

·

CVE-2005-2477

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Naxtor Shopping Cart version 1.0
Description The issue allows remote attackers to obtain sensitive information. This is possibly due to an SQL injection vulnerability, where an error message reveals the path when a cat id with a single quote is used.
Recommendations For Naxtor Shopping Cart version 1.0, consider validating and sanitizing user input to prevent SQL injection attacks, and avoid displaying sensitive information in error messages. As a temporary workaround, restrict access to the shop display products.php file until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2477

Produtos afetados

Naxtor Shopping Cart