xt:Commerce Unspecified SQL Injection Vulnerability
BID:32398
Info
xt:Commerce Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 32398 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6304 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | xt:Commerce |
| Vulnerable: |
xt:Commerce xt:Commerce 3.04 |
| Not Vulnerable: |
xt:Commerce xt:Commerce 3.04 Sp2.1 |
Discussion
xt:Commerce Unspecified SQL Injection Vulnerability
xt:Commerce is prone to an unspecified SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
This issue affects versions prior to xt:Commerce 3.0.4 Sp2.1.
xt:Commerce is prone to an unspecified SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
This issue affects versions prior to xt:Commerce 3.0.4 Sp2.1.
Exploit / POC
xt:Commerce Unspecified SQL Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
xt:Commerce Unspecified SQL Injection Vulnerability
Solution:
A vendor update is available. Please see the references for more information.
Solution:
A vendor update is available. Please see the references for more information.
References
xt:Commerce Unspecified SQL Injection Vulnerability
References:
References:
- Sicherheitspatch für Version 3.0.4 Sp2.1 (xt:Commerce)
- Vendor Homepage (xt:Commerce)