Vulnerabilities > CVE-2004-1806 - SQL Injection vulnerability in Dogpatch Software Cfwebstore 5.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | CFWEBSTORE_SQL_INJECTION.NASL |
description | The remote host is running cfWebStore 5.0.0 or older. There is a flaw in this software that could allow a remote attacker to execute arbitrary SQL statements in the remote database that could in turn be used to gain administrative access on the remote host, read, or modify the content of the remote database. Additionally, cfWebStore is reportedly vulnerable to a cross-site scripting issue. However, Nessus has not tested for this. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12096 |
published | 2004-03-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12096 |
title | cfWebStore Multiple Vulnerabilities (SQLi, XSS) |
code |
|
References
- http://marc.info/?l=bugtraq&m=107911090901744&w=2
- http://secunia.com/advisories/11112
- http://securitytracker.com/id?1009403
- http://www.cfwebstore.com/whatsnewdetail.cfm?WhatsNew__WhatsNewID=43
- http://www.osvdb.org/4229
- http://www.securityfocus.com/bid/9854
- http://www.s-quadra.com/advisories/Adv-20040312.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15447