Lucene search

K
cve[email protected]CVE-2007-2862
HistoryMay 24, 2007 - 7:30 p.m.

CVE-2007-2862

2007-05-2419:30:00
web.nvd.nist.gov
29
cve-2007-2862
sql injection
cubecart
remote attack
arbitrary commands

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.0%

Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification.

Affected configurations

NVD
Node
devellioncubecartMatch3.0.16

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.0%

Related for CVE-2007-2862