CVE-2005-3996

Zen-cart Zen Cart < 1.2.6d - SQL Injection

Title source: rule

Description

SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1354

Scores

EPSS 0.0173
EPSS Percentile 82.5%

Details

CWE
CWE-89
Status published
Products (1)
zen-cart/zen_cart < 1.2.6d
Published Dec 05, 2005
Tracked Since Feb 18, 2026