CVE-2008-3412
31.07.2008, 17:41
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.
Vendor | Product | Version |
---|---|---|
ecshop | epshop | 𝑥 ≤ 2.1.5 |
ecshop | epshop | 2.0.0 |
ecshop | epshop | 2.0.1 |
ecshop | epshop | 2.0.2 |
ecshop | epshop | 2.0.2:a |
ecshop | epshop | 2.0.3 |
ecshop | epshop | 2.0.5 |
ecshop | epshop | 2.1.0 |
ecshop | epshop | 2.1.1 |
ecshop | epshop | 2.1.1:a |
ecshop | epshop | 2.1.1:b |
ecshop | epshop | 2.1.1:c |
ecshop | epshop | 2.1.2 |
ecshop | epshop | 2.1.2:a |
ecshop | epshop | 2.1.2:b |
𝑥
= Vulnerable software versions
References