CVE-2008-1907
Last modified
CVE-2008-1907 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cpcommerce | Cpcommerce | 1.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1907?
How severe is CVE-2008-1907?
How do I fix CVE-2008-1907?
Are you affected by CVE-2008-1907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
