First published: Tue May 27 2008(Updated: )
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mytipper Zogo shop | =1.15.5 | |
Mytipper Zogo shop | =1.16-beta13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2447 is considered to be a high severity SQL injection vulnerability.
To fix CVE-2008-2447, update the Mytipper ZoGo-shop plugin to version 1.16 or later.
CVE-2008-2447 affects Mytipper ZoGo-shop versions 1.15.5 and 1.16 Beta 13.
CVE-2008-2447 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
The 'cat' parameter is exploited in CVE-2008-2447.