CVE-2015-9226
Last modified
CVE-2015-9226 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.. EPSS estimates a 1.98% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alegrocart | Alegrocart | 1.2.8 |
References
- http://packetstormsecurity.com/files/134362/AlegroCart-1.2.8-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Nov/68Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/38727/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/134362/AlegroCart-1.2.8-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Nov/68Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/38727/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9226?
How severe is CVE-2015-9226?
How do I fix CVE-2015-9226?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-9220In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9221In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9222In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9223In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9224In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9225Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-9227PHP remote file inclusion vulnerability in the get_file func…
- CVE-2015-9228In post-new.php in the Photocrati NextGEN Gallery plugin 2.1…
- CVE-2015-9229In the nggallery-manage-gallery page in the Photocrati NextG…4.8
- CVE-2015-9230In the admin/db-backup-security/db-backup-security.php page …4.8
- CVE-2015-9231iTerm2 3.x before 3.1.1 allows remote attackers to discover …
- CVE-2015-9232The Good for Enterprise application 3.0.0.415 for Android do…
Are you affected by CVE-2015-9226?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
