Vulnerabilities > CVE-2005-1503 - SQL Injection vulnerability in MidiCart PHP Search_List.PHP SearchString Parameter

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
midicart-software
exploit available

Summary

Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.

Vulnerable Configurations

Part Description Count
Application
Midicart_Software
1

Exploit-Db

descriptionMidiCart PHP Search_List.PHP SearchString Parameter SQL Injection Vulnerability. CVE-2005-1503. Webapps exploit for php platform
idEDB-ID:25614
last seen2016-02-03
modified2005-05-05
published2005-05-05
reporterExoduks
sourcehttps://www.exploit-db.com/download/25614/
titleMidiCart PHP Search_List.PHP SearchString Parameter SQL Injection Vulnerability