Zen Cart Login.PHP SQL Injection Vulnerability
BID:10378
Info
Zen Cart Login.PHP SQL Injection Vulnerability
| Bugtraq ID: | 10378 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2004 12:00AM |
| Updated: | May 18 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to Oliver Minack <[email protected]>. |
| Vulnerable: |
Zen Cart Web Shopping Cart 1.1.2 d |
| Not Vulnerable: | |
Discussion
Zen Cart Login.PHP SQL Injection Vulnerability
Zen Cart has been reported prone to an SQL injection vulnerability. This is due to an input validation error that fails to validate user input before using it in SQL queries.
This issue may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.
Zen Cart has been reported prone to an SQL injection vulnerability. This is due to an input validation error that fails to validate user input before using it in SQL queries.
This issue may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.
Exploit / POC
Zen Cart Login.PHP SQL Injection Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Zen Cart Login.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Zen Cart Login.PHP SQL Injection Vulnerability
References:
References:
- Vendor Home Page (Zen Cart)
- Zen Cart login.php SQL Injection Vulnerability (Oliver Minack
)