|
Family: CGI abuses --> Category: attack
CubeCart 2.0.6 and Earlier Multiple SQL Injection Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for multiple SQL injection vulnerabilities in CubeCart 2.0.6 and earlier
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is vulnerable to
SQL injection attacks.
Description :
The installed version of CubeCart on the remote host suffers from
multiple SQL injection vulnerabilities due to its failure to sanitize
user input via the 'PHPSESSID' parameter of the 'index.php' script,
the 'product' parameter of the 'tellafriend.php' script, the 'add'
parameter of the 'view_cart.php' script, and the 'product' parameter
of the 'view_product.php' script. A possible hacker can take advantage of
these flaws to manipulate database queries.
See also :
http://archives.neohapsis.com/archives/bugtraq/2005-04/0083.html
Solution :
Upgrade to CubeCart 2.0.7 or later.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|