PT-2014-4260 · Uaepd · Uaepd Shopping Cart Script

Published

2014-01-21

·

Updated

2024-02-14

·

CVE-2014-1618

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UAEPD Shopping Cart Script (affected versions not specified)
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This can be achieved by manipulating the cat id or p id parameter to products.php, or the id parameter to either page.php or news.php.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2014-1618

Affected Products

Uaepd Shopping Cart Script