OScommerce Additional_Images.PHP SQL Injection Vulnerability
BID:15023
Info
OScommerce Additional_Images.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15023 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4677 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2005 12:00AM |
| Updated: | May 29 2007 05:51PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
osCommerce osCommerce 2.2 ms2 060817 Update osCommerce osCommerce 2.2 ms2 05113 update osCommerce osCommerce 2.2 ms2 05112 update osCommerce osCommerce 2.2 ms2 osCommerce osCommerce 2.2 ms1 osCommerce osCommerce 2.2 cvs osCommerce osCommerce 2.1 |
| Not Vulnerable: | |
Discussion
OScommerce Additional_Images.PHP SQL Injection Vulnerability
osCommerce is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
osCommerce is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Exploit / POC
OScommerce Additional_Images.PHP SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
OScommerce Additional_Images.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
OScommerce Additional_Images.PHP SQL Injection Vulnerability
References:
References:
- osCommerce Homepage (osCommerce)