Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-6985

Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 84.1%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2008-6985


Contact Us

Shodan ® - All rights reserved