PT-2007-4294 · Salescart · Salescart Shopping Cart

Published

2007-06-04

·

Updated

2024-08-07

·

CVE-2007-2997

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SalesCart Shopping Cart (affected versions not specified)
Description: The issue concerns SQL injection vulnerabilities in the cgi-bin/reorder2.asp file of SalesCart Shopping Cart, allowing remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. The vendor disputes this issue, stating it was reproducible on an old, out-of-date demo but not on the released product.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2007-2997

Affected Products

Salescart Shopping Cart