PT-2005-2017 · Early Impact · Productcart

Published

2005-04-07

·

Updated

2021-06-15

·

CVE-2005-0994

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProductCart version 2.7
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the Category or resultCnt parameters to the "/advSearch h.asp" API endpoint. There is also a possible vulnerability in the offset parameter to the "/tarinasworld butterflyjournal.asp" API endpoint, although this might be a reporting error.
Recommendations For ProductCart version 2.7, consider restricting access to the /advSearch h.asp and /tarinasworld butterflyjournal.asp API endpoints to minimize the risk of exploitation. Avoid using the Category and resultCnt parameters in the /advSearch h.asp endpoint until the issue is resolved. If the offset parameter vulnerability in /tarinasworld butterflyjournal.asp is confirmed, restrict its use as well.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0994

Affected Products

Productcart