PT-2009-2962 · Script Toko Online · Script Toko Online
K1N9K0Ng
·
Publicado
2009-01-27
·
Atualizado
2017-09-29
·
CVE-2009-0296
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Script Toko Online version 5.01
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. The issue is related to the
cat id parameter in the "shop display products.php" file.Recommendations
For Script Toko Online version 5.01, consider restricting access to the
cat id parameter in the "shop display products.php" file until a patch is available. As a temporary workaround, avoid using the cat id parameter in the affected file to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Script Toko Online