PT-2006-6622 · Infinicart · Infinicart
Benjamin Moss
+1
·
Published
2006-11-17
·
Updated
2024-08-07
·
CVE-2006-5957
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
INFINICART (affected versions not specified)
Description
The issue concerns SQL injection vulnerabilities that could allow remote attackers to execute arbitrary SQL commands. This is possible via several parameters in different ASP files, including the
groupid parameter in "browse group.asp", the productid parameter in "added to cart.asp", and the catid and subid parameters in "browsesubcat.asp". The vendor has disputed the report, stating that the vulnerabilities were only present in an unofficial demo version, not in official released products. However, they have updated the demo version to fix these issues.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinicart