CVE-2010-4147
Avactis Shopping Cart < 1.9.1 - SQL Injection via User-Agent Header
Title source: llmDescription
Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/68647
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/41764
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/44104
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/62559
Patch x_refsource_confirm
http://www.avactis.com/forums/index.php?showtopic=5317
Various Sources x_refsource_misc
http://holisticinfosec.org/content/view/159/45/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/68646
Scores
EPSS
0.0130
EPSS Percentile
67.4%
Details
CWE
CWE-89
Status
published
Products (5)
avactis/avactis_shopping_cart
1.8.0
avactis/avactis_shopping_cart
1.8.1
avactis/avactis_shopping_cart
1.8.2
avactis/avactis_shopping_cart
1.9.0
avactis/avactis_shopping_cart
< 1.9.1
Published
Nov 02, 2010
Tracked Since
Feb 18, 2026