PT-2005-5114 · Cs Cart · Cs-Cart

Published

2005-12-21

·

Updated

2008-09-20

·

CVE-2005-4429

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CS-Cart version 1.3.0
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the sort by and sort order parameters in the "index.php" endpoint.
Recommendations For CS-Cart version 1.3.0, avoid using the sort by and sort order parameters in the "index.php" endpoint until a fix is available. As a temporary workaround, consider restricting access to the "index.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4429

Affected Products

Cs-Cart