Vulnerabilities > CVE-2004-2413 - SQL Injection vulnerability in Virtual Programming VP-ASP Shopproductselect Script
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Invision Power Board 1.3 SSI.PHP Cross-Site Scripting Vulnerability. CVE-2004-2413 . Webapps exploit for php platform |
id | EDB-ID:24199 |
last seen | 2016-02-02 |
modified | 2004-06-14 |
published | 2004-06-14 |
reporter | IMAN Sharafoddin |
source | https://www.exploit-db.com/download/24199/ |
title | Invision Power Board 1.3 SSI.PHP Cross-Site Scripting Vulnerability |