CVE-2004-1580: SQL Injection
Published Dec 31, 2004
·Updated
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Affected Software
1 affected component
Devellion CubeCart=2.0.1
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1580?
CVE-2004-1580 is considered to be of medium severity due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2004-1580?
To resolve CVE-2004-1580, upgrade CubeCart to the latest version that has addressed this SQL injection vulnerability.
3
What are the potential impacts of CVE-2004-1580?
Exploitation of CVE-2004-1580 can lead to unauthorized access to database information and potentially control over the affected application.
4
Who is affected by CVE-2004-1580?
CVE-2004-1580 affects users of CubeCart version 2.0.1.
5
How is CVE-2004-1580 exploited?
CVE-2004-1580 can be exploited by passing malicious SQL commands through the cat_id parameter in the index.php file.