Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php.
References
Link | Resource |
---|---|
http://secunia.com/advisories/10786/ | Patch Vendor Advisory |
http://www.securityfocus.com/archive/1/352598 | Exploit Patch |
http://www.securityfocus.com/bid/9574 | Exploit |
http://www.zone-h.org/en/advisories/read/id=3864/ | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15035 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-12-31 05:00
Updated : 2017-07-11 01:31
NVD link : CVE-2004-2175
Mitre link : CVE-2004-2175
CVE.ORG link : CVE-2004-2175
JSON object : View
Products Affected
all_enthusiast_inc
- reviewpost_php_pro
CWE