Description
SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by BugReport.IR · textwebappsasp
https://www.exploit-db.com/exploits/4988
References (3)
Core 3
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28662
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0314
Exploit x_refsource_confirm
http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1
Scores
EPSS
0.0043
EPSS Percentile
62.7%
Details
CWE
CWE-89
Status
published
Products (2)
shoppingtree/candypress_store
4.1.1.26
shoppingtree/candypress_store
< 4.1
Published
Feb 13, 2008
Tracked Since
Feb 18, 2026