PT-2005-3382 · Naxtor · Naxtor Shopping Cart
John Cobb
·
Published
2005-08-05
·
Updated
2017-07-11
·
CVE-2005-2477
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Naxtor Shopping Cart version 1.0
Description
The issue allows remote attackers to obtain sensitive information. This is possibly due to an SQL injection vulnerability, where an error message reveals the path when a
cat id with a single quote is used.Recommendations
For Naxtor Shopping Cart version 1.0, consider validating and sanitizing user input to prevent SQL injection attacks, and avoid displaying sensitive information in error messages. As a temporary workaround, restrict access to the
shop display products.php file until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Naxtor Shopping Cart