CVE-2013-7193

C2C Forward Auction Creator 2.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.

Exploits (2)

exploitdb WRITEUP VERIFIED
by R3d-D3V!L · textwebappsphp
https://www.exploit-db.com/exploits/38876
exploitdb WRITEUP VERIFIED
by R3d-D3V!L · textwebappsphp
https://www.exploit-db.com/exploits/38877

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101076
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89752
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89755
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64329
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101075

Scores

EPSS 0.0195
EPSS Percentile 83.6%

Details

CWE
CWE-89
Status published
Products (1)
etoshop/c2c_forward_auction_creator 2.0
Published Dec 21, 2013
Tracked Since Feb 18, 2026