Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Felix Maduakor

#26133of 53,635
9.8Total CVSS
Vulnerabilities · 1
PT-2017-8409
9.8
2017-02-15
Modified Ecommerce · Modified Ecommerce Shopsoftware · CVE-2016-3694
**Name of the Vulnerable Software and Affected Versions** modified eCommerce Shopsoftware version 2.0.0.0 revision 9678 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `orders status` or `customers status` parameter to the "api/easybill/easybillcsv.php" endpoint. **Recommendations** For modified eCommerce Shopsoftware version 2.0.0.0 revision 9678, consider restricting access to the "api/easybill/easybillcsv.php" endpoint until a patch is available. As a temporary workaround, avoid using the `orders status` and `customers status` parameters in this endpoint to minimize the risk of exploitation.