CVE-2015-2183
ZeusCart 4 - Authenticated SQL Injection via Admin Backend Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2183. PoCs published by Steffen Rösemann.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Zeuscart v.4, including XSS, SQLi, and information disclosure. It provides technical details, exploit examples, and a timeline of vendor communication.
Description
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via the id parameter in a (1) disporders detail or (2) subadminmgt edit action or (3) cid parameter in an editcurrency action to admin/.
Exploits (1)
This advisory details multiple vulnerabilities in Zeuscart v.4, including XSS, SQLi, and information disclosure. It provides technical details, exploit examples, and a timeline of vendor communication.