PT-2015-5668 · Photocrati · Photocrati

Ayastar

·

Published

2015-03-05

·

Updated

2016-12-03

·

CVE-2015-2216

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Photocrati theme versions 4.x
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the prod id parameter in the ecomm-sizes.php file.
Recommendations For Photocrati theme version 4.x, consider restricting access to the ecomm-sizes.php file until a patch is available, and avoid using the prod id parameter in the affected endpoint.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2216

Affected Products

Photocrati