Описание
SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.
SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2004-2023
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16176
- http://marc.info/?l=bugtraq&m=108489697219781&w=2
- http://secunia.com/advisories/11649
- http://securitytracker.com/id?1010172
- http://www.osvdb.org/6298
- http://www.packetstormsecurity.org/0405-advisories/zencart112d.txt
- http://www.securityfocus.com/archive/1/434237/30/4950/threaded
- http://www.securityfocus.com/bid/10378
- http://www.zen-cart.com/modules/ipb/index.php?showtopic=4835
- http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&orderby=dateD
EPSS
Процентиль: 79%
0.01314
Низкий
CVE ID
Связанные уязвимости
nvd
около 21 года назад
SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.
EPSS
Процентиль: 79%
0.01314
Низкий