Lucene search

K
cveMitreCVE-2007-5261
HistoryOct 06, 2007 - 5:17 p.m.

CVE-2007-5261

2007-10-0617:17:00
CWE-89
mitre
web.nvd.nist.gov
24
cve-2007-5261
sql injection
multicart 1.0
remote attacks
arbitrary commands

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.001

Percentile

49.5%

Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.

Affected configurations

Nvd
Node
iscriptsmulticartMatch1.0
VendorProductVersionCPE
iscriptsmulticart1.0cpe:2.3:a:iscripts:multicart:1.0:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.001

Percentile

49.5%

Related for CVE-2007-5261