7.5

CVE-2004-2108

Exploit
Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QuadcommQ-shop Version2.0
QuadcommQ-shop Version2.1
QuadcommQ-shop Version2.5
QuadcommQ-shop Version2.5_beta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.2% 0.865
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=107488132208229&w=2
http://secunia.com/advisories/10704
http://securitytracker.com/alerts/2004/Jan/1008837.html
http://www.osvdb.org/3698
http://www.osvdb.org/3699
http://www.osvdb.org/3700
http://www.osvdb.org/3701
http://www.osvdb.org/3702
http://www.osvdb.org/3703
http://www.osvdb.org/3704
http://www.osvdb.org/3705
http://www.osvdb.org/3706
http://www.s-quadra.com/advisories/Adv-20040123.txt
Exploit
http://www.securityfocus.com/bid/9481
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/14922