vendor:
SunShop
by:
GulfTech Security Research
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SunShop
Affected Version From: SunShop <= 4.1.4
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:turnkey_web_tools:sunshop
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
SunShop <= 4.1.4 SQL Injection
SunShop shopping cart is a full featured ecommerce solution written in php that allows for web masters to run their own online ecommerce operation. Unfortunately there are a number of SQL Injection issues in SunShop that allow for an attacker to have arbitrary access to the SunShop database where they can access information such as customer and administrator details.
Mitigation:
Users should upgrade to the latest version of SunShop to address these issues.