Vulnerabilities > CVE-2007-3323 - Input Validation vulnerability in Comersus Open Technologies Comersus Cart 7.07

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
comersus-open-technologies
exploit available

Summary

SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.

Vulnerable Configurations

Part Description Count
Application
Comersus_Open_Technologies
1

Exploit-Db

descriptionComersus Cart 7.0.7 comersus_optReviewReadExec.asp id Parameter SQL Injection. CVE-2007-3323. Webapps exploit for asp platform
idEDB-ID:30203
last seen2016-02-03
modified2007-06-20
published2007-06-20
reporterDoz
sourcehttps://www.exploit-db.com/download/30203/
titleComersus Cart 7.0.7 comersus_optReviewReadExec.asp id Parameter SQL Injection