20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=107712159425226&w=2 CVE-2004-0304
WebCortex WebStores2000 - SQL Injection
Record summary
CVE-2004-0304 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebCortex WebStores2000 - SQL InjectionExploitDB exploitby BosenNot analyzed1 file
References
5s-quadra.com
http://www.s-quadra.com/advisories/Adv-20040218.txt 7766vdb entry
http://www.securityfocus.com/bid/7766 webstores-browseitems-sql-injection(15253)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15253 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0304