CVE-2008-2411
Sazcart < 1.5 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a details action.
Exploits (1)
References (6)
Scores
EPSS
0.0090
EPSS Percentile
75.3%
Classification
CWE
CWE-89
Status
draft
Affected Products (3)
sazcart/sazcart
< 1.5
sazcart/sazcart
sazcart/sazcart
Timeline
Published
May 22, 2008
Tracked Since
Feb 18, 2026