BugMall Shopping Cart Multiple Input Validation Vulnerabilities

BugMall Shopping Cart is prone to input-validation vulnerabilities, including an SQL-injection issue and a cross-site scripting issue, because the application fails to sanitize user-supplied input.

A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

BugMall Shopping Cart 2.5 and prior versions are affected.


 

Privacy Statement
Copyright 2010, SecurityFocus