Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-0300
Description:SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-0300
BugTraq ID: 9676
http://www.securityfocus.com/bid/9676
BugTraq ID: 9687
http://www.securityfocus.com/bid/9687
Bugtraq: 20040218 ZH2004-07SA (security advisory): Multiple Sql injection (Google Search)
http://marc.info/?l=bugtraq&m=107712117913185&w=2
http://www.systemsecure.org/advisories/ssadvisory16022004.php
http://www.zone-h.org/en/advisories/read/id=3972/
http://www.osvdb.org/3973
http://securitytracker.com/alerts/2004/Feb/1009092.html
http://secunia.com/advisories/10902/
XForce ISS Database: onlinestorekit-more-sql-injection(15232)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15232




© 1998-2025 E-Soft Inc. All rights reserved.