PT-2008-5147 · Picturespro · Picturespro Photo Cart

~!Dok_Tor!~

·

Published

2008-08-26

·

Updated

2017-09-29

·

CVE-2008-3788

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PICTURESPRO Photo Cart version 3.9
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible due to multiple SQL injection vulnerabilities when magic quotes gpc is disabled. The vulnerable parameters are qtitle, qid, and qyear in the "search.php" endpoint, and email and password in the " login.php" endpoint.
Recommendations For PICTURESPRO Photo Cart version 3.9, consider disabling the magic quotes gpc option or restricting access to the "search.php" and " login.php" endpoints until a patch is available. As a temporary workaround, avoid using the qtitle, qid, qyear, email, and password parameters in the affected endpoints.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3788

Affected Products

Picturespro Photo Cart