First published: Wed Feb 15 2006(Updated: )
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen Cart | =1.2.4.1 | |
Zen Cart | =1.2.1d | |
Zen Cart | =1.2.3d | |
Zen Cart | =1.1.3d | |
Zen Cart | =1.2.1_patch1 | |
Zen Cart | =1.1.1d | |
Zen Cart | =1.1.4d | |
Zen Cart | =1.1.2d | |
Zen Cart | =1.2.5d | |
Zen Cart | =1.2.0d | |
Zen Cart | =1.2.4d | |
Zen Cart | =1.2.2d | |
Zen Cart | =1.2.6d | |
Zen Cart | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0696 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2006-0696, upgrade your Zen Cart installation to version 1.2.7 or later.
CVE-2006-0696 allows remote attackers to execute arbitrary SQL commands, potentially compromising data integrity and confidentiality.
Versions of Zen Cart prior to 1.2.7, including 1.2.6d, 1.2.5d, and earlier, are affected by CVE-2006-0696.
There have been indications that CVE-2006-0696 may be exploited in the wild, making it crucial to apply the necessary updates.