PT-2008-5957 · Uniwin · Uniwin Ecart Professional

Published

2008-10-27

·

Updated

2017-08-08

·

CVE-2008-4746

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Uniwin eCart Professional version 2.0.17
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This is achieved by exploiting unspecified vectors in the search.asp and cartUtil.asp API endpoints.
Recommendations For Uniwin eCart Professional version 2.0.17, consider disabling access to the search.asp and cartUtil.asp endpoints until a patch is available. Restrict input validation to minimize the risk of SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4746

Affected Products

Uniwin Ecart Professional