Lucene search

K
cveMitreCVE-2004-0300
HistoryNov 23, 2004 - 5:00 a.m.

CVE-2004-0300

2004-11-2305:00:00
mitre
web.nvd.nist.gov
27
cve-2004-0300
sql injection
online store kit 3.0
vulnerability
unauthorized access
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.038

Percentile

91.9%

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Affected configurations

Nvd
Node
ecommerce_corporation_onlinestore_kitMatch3.0_lite
OR
ecommerce_corporation_onlinestore_kitMatch3.0_pro
OR
ecommerce_corporation_onlinestore_kitMatch3.0_standard
VendorProductVersionCPE
ecommerce_corporation_onlinestore_kit3.0_litecpe:2.3:a:ecommerce_corporation_online:store_kit:3.0_lite:*:*:*:*:*:*:*
ecommerce_corporation_onlinestore_kit3.0_procpe:2.3:a:ecommerce_corporation_online:store_kit:3.0_pro:*:*:*:*:*:*:*
ecommerce_corporation_onlinestore_kit3.0_standardcpe:2.3:a:ecommerce_corporation_online:store_kit:3.0_standard:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.038

Percentile

91.9%

Related for CVE-2004-0300