CVE-2006-4297: SQL Injection
Published Aug 23, 2006
·Updated
SQL injection vulnerability in shoppingcart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQL commands via id array parameters.
Affected Software
1 affected component
osCommerce oscommerce=2.2_ms2_2006-08-17
Remediation
Patch Available
Patch Available
Event History
Aug 23, 2006
CVE Published
01:04 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4297?
CVE-2006-4297 has a medium severity rating due to its potential for allowing remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-4297?
To fix CVE-2006-4297, upgrade to osCommerce version 2.2 Milestone 2 060817 or later to address the SQL injection vulnerability.
3
What are the potential impacts of CVE-2006-4297?
The potential impacts of CVE-2006-4297 include unauthorized access to the database and manipulation of sensitive data.
4
Which software is affected by CVE-2006-4297?
CVE-2006-4297 affects osCommerce versions before 2.2 Milestone 2 060817.
5
Who can exploit CVE-2006-4297?
Remote attackers can exploit CVE-2006-4297 by sending specially crafted id array parameters to shopping_cart.php.