CVE-2008-3594

MagicScripts E-Store Kit - SQL Injection

Title source: llm

Description

SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mr.SQL · textwebappsphp
https://www.exploit-db.com/exploits/6193

Scores

EPSS 0.0044
EPSS Percentile 62.6%

Classification

CWE
CWE-89
Status draft

Affected Products (4)

magicscripts/e-store_kit-1
magicscripts/e-store_kit-1
magicscripts/e-store_kit-2
magicscripts/e-store_kit-2

Timeline

Published Aug 11, 2008
Tracked Since Feb 18, 2026