[] NeoSense

AFFCommerce Shopping Cart 1.1.4 - 'subcategory.php?cl' SQL Injection

Author: r0t3d3Vil
type: webapps
platform: php
port: nan
date_added: 2005-11-23 
date_updated: 2013-07-03 
verified: 1 
codes: CVE-2005-3914;OSVDB-21070 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/15545/info

AFFCommerce Shopping Cart is prone to multiple SQL injection vulnerabilities.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

AFFCommerce Shopping Cart 1.1.4 is reportedly affected. It is possible that other versions are vulnerable as well.

http://www.example.com/standalone/SubCategory.php?cl=[sql]