ProductCart Login.ASP SQL Injection Vulnerability

BID:8105

Info

ProductCart Login.ASP SQL Injection Vulnerability

Bugtraq ID: 8105
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jul 04 2003 12:00AM
Updated: Jul 04 2003 12:00AM
Credit: Discovery of this vulnerability has been credited to Bosen <[email protected]>.
Vulnerable: Early Impact ProductCart 2.0 br000
Early Impact ProductCart 2.0
Early Impact ProductCart 1.6003
Early Impact ProductCart 1.6002
Early Impact ProductCart 1.5004
Early Impact ProductCart 1.5003 r
Early Impact ProductCart 1.5003
Early Impact ProductCart 1.5002
Early Impact ProductCart 1.6 br003
Early Impact ProductCart 1.6 br001
Early Impact ProductCart 1.6 br
Early Impact ProductCart 1.6 b003
Early Impact ProductCart 1.6 b002
Early Impact ProductCart 1.6 b001
Early Impact ProductCart 1.6 b
Early Impact ProductCart 1.5
Not Vulnerable:

Discussion

ProductCart Login.ASP SQL Injection Vulnerability

ProductCart has been reported prone to an SQL injection vulnerability that may be exploited to bypass the ProductCart authentication system and access the ProductCart administration panel; other attacks may also be possible.

Exploit / POC

ProductCart Login.ASP SQL Injection Vulnerability

The following proof of concept has been supplied:

http://www.example.com/produccart/pdacmin/login.asp?idadmin='' or 1=1--

Solution / Fix

ProductCart Login.ASP SQL Injection Vulnerability

Solution:
The vendor has advised users of ProductCart v2 to contact [email protected] to receive an updated version of "pcadmin/login.asp".

Users of ProductCart 1.5 and earlier are advised to contact [email protected] to obtain the latest version of ProductCart.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report