CVE-2005-1487

Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable
Configurations

Configuration 1 (hide)

cpe:2.3:a:fishnet:fishcart:3.1:*:*:*:*:*:*:*

History

07 Nov 2023, 01:57

Type Values Removed Values Added
Summary ** DISPUTED ** Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable. Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

Information

Published : 2005-05-11 04:00

Updated : 2024-08-07 22:15


NVD link : CVE-2005-1487

Mitre link : CVE-2005-1487

CVE.ORG link : CVE-2005-1487


JSON object : View

Products Affected

fishnet

  • fishcart
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')