vendor:
Store
by:
Sense of Security Labs
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Store
Affected Version From: 4.3.3683.31484
Affected Version To: 4.3.3683.31484
Patch Exists: YES
Related CWE: Not yet assigned
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Sense of Security – Security Advisory – SOS-12-003
Iciniti Store is a web application providing e-commerce and payment solutions. The application suffers from a SQL injection vulnerability in logon_forgot_password.aspx. It fails to validate data supplied in the 'ctlEmail' variable before being used in an SQL query.
Mitigation:
Update is available by contacting Iciniti.