vendor:
Shopmaker Asp
by:
Platen
7,5
CVSS
HIGH
LFI and Blind SQL Injection
22, 89
CWE
Product Name: Shopmaker Asp
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:shopmaker:shopmaker_asp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Shopmaker CMS (bSQL/LFI) Multiple Remote Vulnerabilities
Shopmaker Asp version 2.0 is vulnerable to Local File Inclusion and Blind SQL Injection. An attacker can exploit these vulnerabilities to gain access to sensitive information and execute arbitrary code on the server.
Mitigation:
Apply the latest security patches and ensure that the web application is configured securely.