Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MagicScripts Multiple E-Store Scripts 'viewdetails.php' SQL Injection Vulnerability

Multiple E-Store scripts are prone to an SQL-injection vulnerability because the applications fail to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the vulnerable applications, access or modify data, or exploit latent vulnerabilities in the underlying database.

The following applications are affected:

E-Store Kit-1
E-Store Kit-2
E-Store Kit-1 Pro PayPal Edition
E-Store Kit-2 PayPal Edition







 

Privacy Statement
Copyright 2009, SecurityFocus