CVE Database
/

CVE-2004-0300

Back to search

CVE-2004-0300

Published: Mar 18, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

9676
vdb-entry
x_refsource_BID
9687
vdb-entry
x_refsource_BID
3973
vdb-entry
x_refsource_OSVDB
1009092
vdb-entry
x_refsource_SECTRACK
10902
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now