Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.18290
Kategorie:Web application abuses
Titel:MetaCart E-Shop ProductsByCategory.ASP SQL and XSS Injection Vulnerabilities
Zusammenfassung:Due to a lack of user input validation, the remote version of; MetaCart e-Shop is vulnerable to various SQL injection vulnerabilities and cross site scripting attacks.
Beschreibung:Summary:
Due to a lack of user input validation, the remote version of
MetaCart e-Shop is vulnerable to various SQL injection vulnerabilities and cross site scripting attacks.

Vulnerability Impact:
An attacker may exploit these flaws to execute arbitrary SQL commands against
the remote database or to perform a cross site scripting attack using the remote host.

Solution:
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 13385
BugTraq ID: 13384
BugTraq ID: 13383
BugTraq ID: 13382
BugTraq ID: 13639
CopyrightCopyright (C) 2005 Josh Zlatin-Amishav

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.