CVE Database
/

CVE-2006-4214

Back to search

CVE-2006-4214

Published: Aug 17, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) GPC data to the ipn_get_stored_session function in ipn_main_handler.php, which can be leveraged to modify elements of $_SESSION; and allow remote authenticated users to execute arbitrary SQL commands via (2) a session id within a cookie to whos_online_session_recreate, (3) the quantity field to the add_cart function, (4) an id[] parameter when adding an item to a shopping cart, or (5) a redemption code when checking out (dc_redeem_code parameter to includes/modules/order_total/ot_coupon.php).

VendorProductVersions

n/a

n/a

affected
n/a

References

28144
vdb-entry
x_refsource_OSVDB
ADV-2006-3283
vdb-entry
x_refsource_VUPEN
28145
vdb-entry
x_refsource_OSVDB
19542
vdb-entry
x_refsource_BID
28148
vdb-entry
x_refsource_OSVDB
28147
vdb-entry
x_refsource_OSVDB
21484
third-party-advisory
x_refsource_SECUNIA
28146
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now