CVE-2005-1487
CVE-2005-1487
Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/25603unverifiedexploitdbwww.exploit-db.com/exploits/25604unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://marc.info/?l=bugtraq&m=111530799109755&w=2http://secunia.com/advisories/15232/https://exchange.xforce.ibmcloud.com/vulnerabilities/20386http://www.digitalparadox.org/advisories/fishc.txthttp://www.osvdb.org/16282http://www.osvdb.org/16283http://www.securityfocus.com/archive/1/457754/100/200/threadedhttp://www.securityfocus.com/bid/13499