Vulnerability Description
Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the searchTopCategoryID parameter to search_result.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valdersoft | Shopping Cart | 3.0 |
References
- http://securitytracker.com/id?1013565ExploitPatch
- http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2ExploitVendor Advisory
- http://securitytracker.com/id?1013565ExploitPatch
- http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2ExploitVendor Advisory
FAQ
What is CVE-2005-0907?
CVE-2005-0907 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.p...
How severe is CVE-2005-0907?
CVE-2005-0907 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0907?
Check the references section above for vendor advisories and patch information. Affected products include: Valdersoft Shopping Cart.