Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lo$T

#36096of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2010-2442
7.5
2010-02-23
Jtl · Jtl-Shop · CVE-2010-0691
**Name of the Vulnerable Software and Affected Versions** JTL-Shop version 2 **Description** A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the `s` parameter in the `druckansicht.php` file. **Recommendations** For JTL-Shop version 2, avoid using the `s` parameter in the `druckansicht.php` file until a patch is available. As a temporary workaround, consider restricting access to the `druckansicht.php` file to minimize the risk of exploitation.