CVE-2012-5317

Bigware Shop <2.1.5 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in main_bigware_43.php in Bigware Shop before 2.1.5 allows remote attackers to execute arbitrary SQL commands via the lastname parameter in a process action.

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-01/0143.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51640
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47713

Scores

EPSS 0.0132
EPSS Percentile 68.0%

Details

CWE
CWE-89
Status published
Products (2)
bigware/bigware_shop 2.0
bigware/bigware_shop < 2.1.4
Published Oct 08, 2012
Tracked Since Feb 18, 2026