CVE-2014-5104

Ol-commerce - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to affiliate_show_banner.php, (3) country parameter in a process action to create_account.php, or (4) entry_country_id parameter in an edit action to admin/create_account.php.

Exploits (4)

exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39345
exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39343
exploitdb WRITEUP VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39344
exploitdb WORKING POC VERIFIED
by AtT4CKxT3rR0r1ST · textwebappsphp
https://www.exploit-db.com/exploits/39346

References (2)

Core 2

Scores

EPSS 0.0091
EPSS Percentile 76.0%

Details

CWE
CWE-89
Status published
Products (1)
ol-commerce_project/ol-commerce 2.1.1
Published Jul 28, 2014
Tracked Since Feb 18, 2026