CVE-2009-3309
CF ShopKart 5.4 beta - SQL Injection via index.cfm itemid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3309. PoCs published by learn3r hacker.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in CF ShopKart version 5.4 beta or lower. The vulnerability allows an attacker to inject malicious SQL queries via the 'itemid' parameter, potentially leading to information disclosure.
Description
SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in CF ShopKart version 5.4 beta or lower. The vulnerability allows an attacker to inject malicious SQL queries via the 'itemid' parameter, potentially leading to information disclosure.