Vulnerability Details CVE-2004-2108
Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 86.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-2108
-
cpe:2.3:a:quadcomm:q-shop:2.0
-
cpe:2.3:a:quadcomm:q-shop:2.1
-
cpe:2.3:a:quadcomm:q-shop:2.5
-
cpe:2.3:a:quadcomm:q-shop:2.5_beta