103365vdb entry
http://osvdb.org/show/osvdb/103365 CVE-2014-10033
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
Record summary
CVE-2014-10033 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBosCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL InjectionExploitDB exploitby Ahmed Aboul-ElaNot analyzed1 file
References
631515exploit
http://www.exploit-db.com/exploits/31515 secgeek.net
http://www.secgeek.net/oscommerce-v2x-sql-injection-vulnerability oscommerce-geozones-sql-injection(91113)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/91113 github.comConfirmation
https://github.com/gburton/oscommerce2/commit/e4d90eccd7d9072ebe78da4c38fb048bfe31c902 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-10033