CVE Vulnerabilities

CVE-2003-0522

Published: Aug 18, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.

Affected Software

NameVendorStart VersionEnd Version
ProductcartEarly_impact1.5 (including)1.5 (including)
ProductcartEarly_impact1.6b (including)1.6b (including)
ProductcartEarly_impact1.6b001 (including)1.6b001 (including)
ProductcartEarly_impact1.6b002 (including)1.6b002 (including)
ProductcartEarly_impact1.6b003 (including)1.6b003 (including)
ProductcartEarly_impact1.6br (including)1.6br (including)
ProductcartEarly_impact1.6br001 (including)1.6br001 (including)
ProductcartEarly_impact1.6br003 (including)1.6br003 (including)
ProductcartEarly_impact1.5002 (including)1.5002 (including)
ProductcartEarly_impact1.5003 (including)1.5003 (including)
ProductcartEarly_impact1.5003r (including)1.5003r (including)
ProductcartEarly_impact1.5004 (including)1.5004 (including)
ProductcartEarly_impact1.6002 (including)1.6002 (including)
ProductcartEarly_impact1.6003 (including)1.6003 (including)
ProductcartEarly_impact2 (including)2 (including)
ProductcartEarly_impact2br000 (including)2br000 (including)

References