CVE

Id
8728  
CVE No.
CVE-2004-0300  
Status
Candidate  
Description
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.  
Phase
Modified (20051204)  
Votes
NOOP(4) Armstrong, Cole, Cox, Wall  
Comments