42711Third-party advisory
http://secunia.com/advisories/42711 CVE-2010-4845
Projekt Shop - 'details.php' Multiple SQL Injections
Record summary
CVE-2010-4845 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBProjekt Shop - 'details.php' Multiple SQL InjectionsExploitDB exploitby DeadLy DeMonNot analyzed1 file
References
515773exploit
http://www.exploit-db.com/exploits/15773 45506vdb entry
http://www.securityfocus.com/bid/45506 projektshop-details-sql-injection(64205)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/64205 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-4845