CVE-2009-4060

SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
cubecartcubecart
𝑥
≤ 4.3.6
cubecartcubecart
3.0.0
cubecartcubecart
3.0.1
cubecartcubecart
3.0.2
cubecartcubecart
3.0.3
cubecartcubecart
3.0.4
cubecartcubecart
3.0.5
cubecartcubecart
3.0.6
cubecartcubecart
3.0.7
cubecartcubecart
3.0.8
cubecartcubecart
3.0.9
cubecartcubecart
3.0.10
cubecartcubecart
3.0.11
cubecartcubecart
3.0.12
cubecartcubecart
3.0.13
cubecartcubecart
3.0.14
cubecartcubecart
3.0.15
cubecartcubecart
3.0.16
cubecartcubecart
3.0.17
cubecartcubecart
3.0.18
cubecartcubecart
3.0.19
cubecartcubecart
3.0.20
cubecartcubecart
4.0.0
cubecartcubecart
4.0.0:beta_2
cubecartcubecart
4.0.0:beta_3
cubecartcubecart
4.0.0:rc_1
cubecartcubecart
4.0.1
cubecartcubecart
4.0.2
cubecartcubecart
4.0.3
cubecartcubecart
4.1.0
cubecartcubecart
4.1.0:rc_1
cubecartcubecart
4.1.0:rc_2
cubecartcubecart
4.1.1
cubecartcubecart
4.2.0
cubecartcubecart
4.2.1
cubecartcubecart
4.2.2
cubecartcubecart
4.2.3
cubecartcubecart
4.3.0
cubecartcubecart
4.3.1
cubecartcubecart
4.3.2
cubecartcubecart
4.3.3
cubecartcubecart
4.3.4
cubecartcubecart
4.3.5
𝑥
= Vulnerable software versions