SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpcommerce | Cpcommerce | 1.0.5.1 (including) | 1.0.5.1 (including) |
Cpcommerce | Cpcommerce | 1.0.6 (including) | 1.0.6 (including) |
Cpcommerce | Cpcommerce | 1.0.7 (including) | 1.0.7 (including) |
Cpcommerce | Cpcommerce | 1.0.7.1 (including) | 1.0.7.1 (including) |
Cpcommerce | Cpcommerce | 1.0.7.2 (including) | 1.0.7.2 (including) |
Cpcommerce | Cpcommerce | 1.0.7.3 (including) | 1.0.7.3 (including) |
Cpcommerce | Cpcommerce | 1.0.7.4 (including) | 1.0.7.4 (including) |
Cpcommerce | Cpcommerce | 1.0.8 (including) | 1.0.8 (including) |
Cpcommerce | Cpcommerce | 1.0.9 (including) | 1.0.9 (including) |
Cpcommerce | Cpcommerce | 1.0.9a (including) | 1.0.9a (including) |