vendor:
Zen Cart
by:
Secunia Research
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Zen Cart
Affected Version From: <= 1.3.8a
Affected Version To: <= 1.3.8a
Patch Exists: YES
Related CWE: CVE-2008-6985
CPE: a:zen_venture:zen_cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
Zen Cart SQL Injection
Zen Cart is a full featured open source ecommerce web application written in php that allows users to build, run and promote their own online store. Unfortunately there are multiple SQL Injection issues in Zen Cart that may allow an attacker to execute arbitrary SQL queries on the underlying database. This may allow for an attacker to gather username and password information, among other things. An updated version of Zen Cart has been released to address these issues and users are encouraged to upgrade as soon as possible.
Mitigation:
Upgrade to the latest version of Zen Cart