CVE Database
/

CVE-2009-4571

Back to search

CVE-2009-4571

Published: Jan 5, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action, the (3) module_id parameter in an admin/module_form action, the (4) user_id parameter in an admin/user_form action, the (5) vendor_category_id parameter in a vendor/vendor_category_form action, the (6) user_id parameter in a store/user_form action, the (7) payment_method_id parameter in a store/payment_method_form action, the (8) tax_rate_id parameter in a tax/tax_form action, or the (9) category parameter in a shop/browse action. NOTE: the product_id vector is already covered by CVE-2008-0681.

VendorProductVersions

n/a

n/a

affected
n/a

References

31948
third-party-advisory
x_refsource_SECUNIA
37227
vdb-entry
x_refsource_BID
phpshop-id-sql-injection(54584)
vdb-entry
x_refsource_XF
20091206 PhpShop Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now