CVE-2008-6985

Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
zen-cartzen_cart
1.2.0d:d
zen-cartzen_cart
1.2.1_patch1:_patch1
zen-cartzen_cart
1.2.1d:d
zen-cartzen_cart
1.2.2d:d
zen-cartzen_cart
1.2.3d:d
zen-cartzen_cart
1.2.4.1
zen-cartzen_cart
1.2.4d:d
zen-cartzen_cart
1.2.5d:d
zen-cartzen_cart
1.2.6d:d
zen-cartzen_cart
1.3
zen-cartzen_cart
1.3.2
zen-cartzen_cart
1.3.5
zen-cartzen_cart
1.3.6
zen-cartzen_cart
1.3.7
zen-cartzen_cart
1.3.8
zen-cartzen_cart
1.3.8a:a
𝑥
= Vulnerable software versions