Vulnerability   
Search   
    Search 202850 CVE descriptions
and 87302 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11785
Category:CGI abuses
Title:ProductCart SQL Injection
Summary:NOSUMMARY
Description:Description:

The remote host is using the ProductCart software suite.

This set of CGIs is vulnerable to a SQL injection bug which may allow
an attacker to take the control of the server as an administrator.
From there, he can obtain the list of customers, steal their credit
card information and more.

In addition to this, this software is vulnerable to various
file disclosure and cross site scripting flaws.

Solution : Upgrade to the latest version of ProductCart
Risk factor : High

Cross-Ref: BugTraq ID: 8103
BugTraq ID: 8105
BugTraq ID: 8108
BugTraq ID: 8112
CopyrightThis script is Copyright (C) 2003 Tenable Network Security

This is only one of 87302 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.