Vulnerabilities > CVE-2004-1806 - Unspecified vulnerability in Dogpatch Software Cfwebstore 5.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN dogpatch-software
nessus
Summary
SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | CFWEBSTORE_SQL_INJECTION.NASL |
description | The remote host is running cfWebStore 5.0.0 or older. There is a flaw in this software that could allow a remote attacker to execute arbitrary SQL statements in the remote database that could in turn be used to gain administrative access on the remote host, read, or modify the content of the remote database. Additionally, cfWebStore is reportedly vulnerable to a cross-site scripting issue. However, Nessus has not tested for this. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12096 |
published | 2004-03-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12096 |
title | cfWebStore Multiple Vulnerabilities (SQLi, XSS) |
code |
|
References
- http://marc.info/?l=bugtraq&m=107911090901744&w=2
- http://marc.info/?l=bugtraq&m=107911090901744&w=2
- http://secunia.com/advisories/11112
- http://secunia.com/advisories/11112
- http://securitytracker.com/id?1009403
- http://securitytracker.com/id?1009403
- http://www.cfwebstore.com/whatsnewdetail.cfm?WhatsNew__WhatsNewID=43
- http://www.cfwebstore.com/whatsnewdetail.cfm?WhatsNew__WhatsNewID=43
- http://www.osvdb.org/4229
- http://www.osvdb.org/4229
- http://www.securityfocus.com/bid/9854
- http://www.securityfocus.com/bid/9854
- http://www.s-quadra.com/advisories/Adv-20040312.txt
- http://www.s-quadra.com/advisories/Adv-20040312.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15447
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15447