Vulnerability Description
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hpecs Shopping Cart | Hpecs Shopping Cart | All versions |
References
- http://secunia.com/advisories/22904Vendor Advisory
- http://securityreason.com/securityalert/1879
- http://www.securityfocus.com/archive/1/451595/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4535
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30287
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30288
- https://www.exploit-db.com/exploits/2782
- http://secunia.com/advisories/22904Vendor Advisory
- http://securityreason.com/securityalert/1879
- http://www.securityfocus.com/archive/1/451595/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4535
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30287
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30288
- https://www.exploit-db.com/exploits/2782
FAQ
What is CVE-2006-5962?
CVE-2006-5962 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) sea...
How severe is CVE-2006-5962?
CVE-2006-5962 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5962?
Check the references section above for vendor advisories and patch information. Affected products include: Hpecs Shopping Cart Hpecs Shopping Cart.