PT-2009-1589 · Mytipper · Mytipper Zogo-Shop Plugin For E107

Noge

·

Published

2009-02-11

·

Updated

2017-09-29

·

CVE-2008-6114

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mytipper Zogo-shop plugin for e107 version 1.15.4
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting a SQL injection vulnerability in the product details.php file via the product parameter.
Recommendations For Mytipper Zogo-shop plugin for e107 version 1.15.4, consider restricting access to the product details.php file until a patch is available. Avoid using the product parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6114

Affected Products

Mytipper Zogo-Shop Plugin For E107