CVE Vulnerabilities

CVE-2007-2959

Published: May 31, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.

Affected Software

Name Vendor Start Version End Version
Cpcommerce Cpcommerce 1.0.5.1 (including) 1.0.5.1 (including)
Cpcommerce Cpcommerce 1.0.6 (including) 1.0.6 (including)
Cpcommerce Cpcommerce 1.0.7 (including) 1.0.7 (including)
Cpcommerce Cpcommerce 1.0.7.1 (including) 1.0.7.1 (including)
Cpcommerce Cpcommerce 1.0.7.2 (including) 1.0.7.2 (including)
Cpcommerce Cpcommerce 1.0.7.3 (including) 1.0.7.3 (including)
Cpcommerce Cpcommerce 1.0.7.4 (including) 1.0.7.4 (including)
Cpcommerce Cpcommerce 1.0.8 (including) 1.0.8 (including)
Cpcommerce Cpcommerce 1.0.9 (including) 1.0.9 (including)
Cpcommerce Cpcommerce 1.0.9a (including) 1.0.9a (including)

References