vendor:
BazaarBuilder Shopping Cart Software
by:
XaDoS
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: BazaarBuilder Shopping Cart Software
Affected Version From: 5
Affected Version To: 5
Patch Exists: YES
Related CWE: N/A
CPE: a:bazaarbuilder:bazaarbuilder_shopping_cart_software
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Joomla component: BazaarBuilder Shopping Cart Software v.5.0 sql injection
A vulnerability exists in Joomla component BazaarBuilder Shopping Cart Software v.5.0 which allows an attacker to inject arbitrary SQL commands. This can be exploited to gain access to the admin panel and extract sensitive information from the database.
Mitigation:
Upgrade to the latest version of BazaarBuilder Shopping Cart Software v.5.0 or apply the patch provided by the vendor.