PT-2010-3483 · Unknown · Repairshop2
Published
2010-05-07
·
Updated
2010-06-13
·
CVE-2010-1857
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RepairShop2 version 1.9.023 Trial
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
prod parameter in a "products.details" action when magic quotes gpc is disabled.Recommendations
For version 1.9.023 Trial, consider disabling the
products.details action or restricting access to it until a fix is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Repairshop2