vendor:
MWOpen E-Commerce
by:
KiNgOfThEwOrLd
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: MWOpen E-Commerce
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
MWOpen E-Commerce All Versions “leggi_commenti.asp” SQL Injection
The vulnerability allows an attacker to execute arbitrary SQL commands on the target system by injecting malicious SQL code into the 'id' parameter of the 'leggi_commenti.asp' page. By exploiting this vulnerability, an attacker can retrieve sensitive information from the database, such as passwords.
Mitigation:
The vendor should implement proper input validation and parameterized queries to prevent SQL injection attacks. Users are advised to update to the latest version of MWOpen E-Commerce that addresses this vulnerability.