|
Family: CGI abuses --> Category: attack
ProductCart Multiple SQL Injection Vulnerabilities (2) Vulnerability Scan
Vulnerability Scan Summary Checks for multiple SQL injection vulnerabilities (2) in ProductCart
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains an ASP application that is affected by
multiple SQL injection issues.
Description :
The remote host is running a version of the ProductCart shopping cart
software that fails to properly sanitize user-supplied input before
using it in SQL queries. A possible hacker may be able to exploit these
flaws to alter database queries, disclose sensitive information, or
conduct other such attacks. Possible attack vectors include the
'idcategory' parameter of the 'viewPrd.asp' script, the 'lid'
parameter of the 'editCategories.asp' script, the 'idc' parameter of
the 'modCustomCardPaymentOpt.asp' script, and the 'idccr' parameter of
the 'OptionFieldsEdit.asp' script.
See also :
http://archives.neohapsis.com/archives/bugtraq/2005-07/0521.html
http://echo.or.id/adv/adv16-theday-2005.txt
Solution :
Unknown at this time.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|