Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the searchTopCategoryID parameter to search_result.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-03-29T05:00:00

Updated: 2024-08-07T21:28:29.068Z

Reserved: 2005-03-29T00:00:00

Link: CVE-2005-0907

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-05-02T04:00:00.000

Modified: 2008-09-05T20:47:39.473

Link: CVE-2005-0907

cve-icon Redhat

No data.