PT-2007-4294 · Salescart · Salescart Shopping Cart
Published
2007-06-04
·
Updated
2024-08-07
·
CVE-2007-2997
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SalesCart Shopping Cart (affected versions not specified)
Description:
The issue concerns SQL injection vulnerabilities in the cgi-bin/reorder2.asp file of SalesCart Shopping Cart, allowing remote attackers to execute arbitrary SQL commands via the
password field and other unspecified vectors. The vendor disputes this issue, stating it was reproducible on an old, out-of-date demo but not on the released product.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salescart Shopping Cart