CVE-2004-0300

Online Store Kit 3.0 - SQL Injection via shop.php cat Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2004-0300. PoCs published by G00db0y, David Sopas Ferreira.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Online Store Kit, where insufficient input sanitization allows attackers to manipulate database queries via the URI parameter 'cat_manufacturer'. This can lead to information disclosure, including administrator password hashes.

Description

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Exploits (4)

exploitdb WRITEUP VERIFIED
by G00db0y · textwebappsphp
https://www.exploit-db.com/exploits/23719

The provided text describes a SQL injection vulnerability in Online Store Kit, where insufficient input sanitization allows attackers to manipulate database queries via the URI parameter 'cat_manufacturer'. This can lead to information disclosure, including administrator password hashes.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Online Store Kit (version not specified)
No auth needed
Prerequisites: Access to the vulnerable endpoint · Knowledge of SQL injection techniques
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by G00db0y · textwebappsphp
https://www.exploit-db.com/exploits/23718

The provided text describes a SQL injection vulnerability in Online Store Kit, where insufficient input sanitization allows attackers to manipulate database queries via the 'cat' parameter in the URI. This can lead to information disclosure, including the administrator password hash.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Online Store Kit
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by G00db0y · textwebappsphp
https://www.exploit-db.com/exploits/23720

The provided text describes a SQL injection vulnerability in Online Store Kit, where insufficient input sanitization allows attackers to manipulate database queries via the URI. It mentions the potential to disclose the administrator password hash but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Online Store Kit
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by David Sopas Ferreira · textwebappsphp
https://www.exploit-db.com/exploits/23711

The provided text describes SQL injection and XSS vulnerabilities in Online Store Kit 3.0 via the 'id' parameter in 'more.php'. It lacks executable exploit code but references known issues.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Online Store Kit 3.0
No auth needed
Prerequisites: Access to the vulnerable 'more.php' script
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9676
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9687
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3973
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107712117913185&w=2
Various Sources x_refsource_misc
http://www.zone-h.org/en/advisories/read/id=3972/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/alerts/2004/Feb/1009092.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/10902/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15232

Scores

EPSS 0.0517
EPSS Percentile 91.4%

Details

Status published
Products (3)
ecommerce_corporation_online/store_kit 3.0_lite
ecommerce_corporation_online/store_kit 3.0_pro
ecommerce_corporation_online/store_kit 3.0_standard
Published Nov 23, 2004
Tracked Since Feb 18, 2026