PT-2008-3883 · Sazcart · Sazcart
Joss
·
Published
2008-05-22
·
Updated
2018-10-11
·
CVE-2008-2411
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SazCart versions 1.5.1 and earlier
Description:
The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the
prodid parameter in a "details" action when magic quotes gpc is disabled.Recommendations:
For SazCart versions 1.5.1 and earlier, consider disabling the
prodid parameter in the "details" action until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sazcart