CVE-2005-1487

FishCart 3.1 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

Exploits (2)

exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsphp
https://www.exploit-db.com/exploits/25604
exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsphp
https://www.exploit-db.com/exploits/25603

Scores

EPSS 0.0224
EPSS Percentile 84.3%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

fishnet/fishcart

Timeline

Published May 11, 2005
Tracked Since Feb 18, 2026