vendor:
Proticaret E-commerce Script
by:
BGA Security Team
9,8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Proticaret E-commerce Script
Affected Version From: v3.0
Affected Version To: v3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:promist_bilgi_iletisim_teknolojileri_a.s:proticaret_e-commerce_script
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Remote, Unauthenticated
2014
Proticaret E-Commerce Script v3.0 >= SQL Injection
BGA Security Team discovered an SQL injection vulnerability in Proticaret E-Commerce Script v3.0. The vulnerability is remotely exploitable and allows an attacker to gain access to the database of the application. The vulnerability is caused due to the application not properly sanitizing user-supplied input before using it in an SQL query. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the application. This will allow the attacker to gain access to the database of the application.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of the application.