Vulnerabilities > CVE-2004-2413 - SQL Injection vulnerability in Virtual Programming VP-ASP Shopproductselect Script

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
virtual-programming
exploit available

Summary

SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.

Exploit-Db

descriptionInvision Power Board 1.3 SSI.PHP Cross-Site Scripting Vulnerability. CVE-2004-2413 . Webapps exploit for php platform
idEDB-ID:24199
last seen2016-02-02
modified2004-06-14
published2004-06-14
reporterIMAN Sharafoddin
sourcehttps://www.exploit-db.com/download/24199/
titleInvision Power Board 1.3 SSI.PHP Cross-Site Scripting Vulnerability