PT-2005-3382 · Naxtor · Naxtor Shopping Cart

John Cobb

·

Published

2005-08-05

·

Updated

2017-07-11

·

CVE-2005-2477

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Naxtor Shopping Cart version 1.0
Description The issue allows remote attackers to obtain sensitive information. This is possibly due to an SQL injection vulnerability, where an error message reveals the path when a cat id with a single quote is used.
Recommendations For Naxtor Shopping Cart version 1.0, consider validating and sanitizing user input to prevent SQL injection attacks, and avoid displaying sensitive information in error messages. As a temporary workaround, restrict access to the shop display products.php file until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2477

Affected Products

Naxtor Shopping Cart