CVE-2005-3914
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-3914. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in AFFCommerce Shopping Cart 1.1.4, where the 'cl' parameter in SubCategory.php is vulnerable to malicious SQL input. No actual exploit code is included, only a description and example URL.
Description
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
Exploits (3)
The provided text describes a SQL injection vulnerability in AFFCommerce Shopping Cart 1.1.4, where the 'cl' parameter in SubCategory.php is vulnerable to malicious SQL input. No actual exploit code is included, only a description and example URL.
The provided text describes a SQL injection vulnerability in AFFCommerce Shopping Cart 1.1.4, where the 'item_id' parameter in 'ItemReview.php' is susceptible to malicious SQL input. No actual exploit code is included, only a description and example URL.
The provided text describes a SQL injection vulnerability in AFFCommerce Shopping Cart 1.1.4, where the 'item_id' parameter in 'ItemInfo.php' is susceptible to malicious SQL input. No actual exploit code is included, only a description and an example URL.