vendor:
AShop Deluxe
by:
n0c0py - a.k.a 5iR. 4b03D
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: AShop Deluxe
Affected Version From: 4.x
Affected Version To: 4.x
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Ashop Deluxe 4.x Remote SQL inJection Exploit
AShop Deluxe shopping cart software automates the processing of online orders and payments. It is a shopping cart plus an array of specialized tools to support various types of products and selling styles. The system automates redundant tasks, organizes data, and simplifies the daily operations of an online store. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands and gain access to sensitive data in the back-end database.
Mitigation:
Apply the patch provided by the vendor.