Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-1907 (cpCommerce)

BugsAlert Home > CVE-2008-1907 (cpCommerce)
 
 

Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1907

Learn more about CVE-2008-1907 (cpCommerce)
 
Tags: cve-2008-1907 cpcommerce

Related Items

      Sun Java System Web Proxy Server FTP Subsystem Buffer Overflow

      CVE-2008-1188 (JRE, JDK)

      Mandriva: Updated libpng packages fix multiple

      Vuln: Jokes Site Script 'categorie' Parameter SQL Injection Vulnerability

      CVE-2008-1463 (SecureSphere MX Management Server)

      FrSIRT - Zope PythonScripts Processing Denial of Service Vulnerability

      Avaya CMS Solaris TCP Implementation SYN Flood Denial of Service

 

Pixel