CVE-2007-0224
VP-ASP Shopping Cart <= 6.09 - SQL Injection via LoginLastname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0224. PoCs published by ajann.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in VP-ASP Shopping Cart 6.09. The SQLi allows arbitrary query execution via the 'LoginLastname' parameter, while the XSS is triggered via the 'msg' parameter in 'shopcustadmin.asp'.
Description
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in VP-ASP Shopping Cart 6.09. The SQLi allows arbitrary query execution via the 'LoginLastname' parameter, while the XSS is triggered via the 'msg' parameter in 'shopcustadmin.asp'.