CVE-2004-0300
Summary
| CVE | CVE-2004-0300 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-11-23 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ecommerce Corporation Online | Store Kit | 3.0_lite | All | All | All |
| Application | Ecommerce Corporation Online | Store Kit | 3.0_pro | All | All | All |
| Application | Ecommerce Corporation Online | Store Kit | 3.0_standard | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'ZH2004-07SA (security advisory): Multiple Sql injection' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Ecommerce Corporation Online Store Kit Multiple SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Zone-H.org * Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.zone-h.org | |
| www.osvdb.org/3973 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - Online Store Kit Input Validation Flaws in Several Scripts Permits SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| *SystemSecure.org Advisory* | af854a3a-2127-422b-91ae-364da2661108 | www.systemsecure.org | |
| Secunia - Advisories - Online Store Kit SQL Injection and Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ecommerce Corporation Online Store Kit More.PHP Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.