Vulnerabilities
Vulnerable Software
Abantecart:  >> Abantecart  >> 1.4.2  Security Vulnerabilities
SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind injection via SLEEP(), and UNION-based injection to extract arbitrary data.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-08-27
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.
CVSS Score
7.5
EPSS Score
0.008
Published
2025-08-26


Contact Us

Shodan ® - All rights reserved