CVE-2007-0142
ShopStoreNow E-commerce Shopping Cart - SQL Injection via CatID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0142. PoCs published by IbnuSina.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Shopstorenow E-commerce Shopping Cart by injecting a malicious SQL query via the 'CatID' parameter. The query attempts to extract table names from the database's information_schema, confirming the vulnerability.
Description
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Shopstorenow E-commerce Shopping Cart by injecting a malicious SQL query via the 'CatID' parameter. The query attempts to extract table names from the database's information_schema, confirming the vulnerability.