Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2997

Опубликовано: 04 июн. 2007
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:salescart:shopping_cart:*:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01262
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

** DISPUTED ** Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product."

EPSS

Процентиль: 79%
0.01262
Низкий

7.5 High

CVSS2

Дефекты

CWE-89