10

CVE-2007-4121

Exploit
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://outlaw.aria-security.info/?p=11
Exploit
http://secunia.com/advisories/26277
Vendor Advisory
http://securityreason.com/securityalert/2944
http://www.securityfocus.com/archive/1/475062/100/0/threaded
http://www.securityfocus.com/bid/25125
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/35680