Описание
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
Ссылки
Уязвимые конфигурации
Конфигурация 1Версия до 4.2 (включая)
cpe:2.3:a:cyberstrong:eshop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.05855
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
EPSS
Процентиль: 93%
0.05855
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other