CVE-2008-6986

EUVD-2008-6945
SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the products_id array parameter in a multiple_products_add_product action, a different vulnerability than CVE-2008-6985.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
zen-cartzen_cart
1.3
zen-cartzen_cart
1.3.0.2
zen-cartzen_cart
1.3.2
zen-cartzen_cart
1.3.5
zen-cartzen_cart
1.3.6
zen-cartzen_cart
1.3.7
zen-cartzen_cart
1.3.8
zen-cartzen_cart
1.3.8a:a
𝑥
= Vulnerable software versions