First published: Wed Aug 23 2006(Updated: )
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQL commands via id array parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oscommerce Oscommerce | =2.2_ms2_2006-08-17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4297 has a medium severity rating due to its potential for allowing remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-4297, upgrade to osCommerce version 2.2 Milestone 2 060817 or later to address the SQL injection vulnerability.
The potential impacts of CVE-2006-4297 include unauthorized access to the database and manipulation of sensitive data.
CVE-2006-4297 affects osCommerce versions before 2.2 Milestone 2 060817.
Remote attackers can exploit CVE-2006-4297 by sending specially crafted id array parameters to shopping_cart.php.