vendor:
LiteCommerce
by:
k1tk4t
5.5
CVSS
MEDIUM
Remote SQL Injection
89
CWE
Product Name: LiteCommerce
Affected Version From: LiteCommerce 2004
Affected Version To: LiteCommerce not specified
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
litecommerce Copyright © 2004 – Remote SQL Injection
This exploit allows an attacker to perform a remote SQL injection attack on LiteCommerce. By injecting a specially crafted query, the attacker can retrieve the login and password information from the xlite_profiles table. The exploit may not work on the latest version of LiteCommerce as it does not generate an error message.
Mitigation:
To mitigate this vulnerability, it is recommended to update LiteCommerce to the latest version.