PT-2005-3382 · Naxtor · Naxtor Shopping Cart
John Cobb
·
Publicado
2005-08-05
·
Atualizado
2017-07-11
·
CVE-2005-2477
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Naxtor Shopping Cart version 1.0
Description
The issue allows remote attackers to obtain sensitive information. This is possibly due to an SQL injection vulnerability, where an error message reveals the path when a
cat id with a single quote is used.Recommendations
For Naxtor Shopping Cart version 1.0, consider validating and sanitizing user input to prevent SQL injection attacks, and avoid displaying sensitive information in error messages. As a temporary workaround, restrict access to the
shop display products.php file until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Naxtor Shopping Cart