PT-2005-4739 · Asps · Asps Shopping Cart Lite+1
Publicado
2005-12-05
·
Atualizado
2008-09-20
·
CVE-2005-4003
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ASPS Shopping Cart Professional versions 2.9d and earlier
ASPS Shopping Cart Lite versions 2.1 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
srch product name parameter to "adv search.asp" and the b search parameter to "bsearch.asp".Recommendations
For ASPS Shopping Cart Professional versions 2.9d and earlier, consider restricting access to the adv search.asp and bsearch.asp pages until a fix is available.
For ASPS Shopping Cart Lite versions 2.1 and earlier, avoid using the
srch product name and b search parameters in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Asps Shopping Cart Lite
Asps Shopping Cart Professional