CVE-2008-3412: SQL Injection
Published Jul 31, 2008
·Updated
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) proshow or (2) disppro action to the default URI.
Affected Software
15 affected components
ECShop EPShop=2.1.1-c
ECShop EPShop=2.0.2-a
ECShop EPShop=2.0.2
ECShop EPShop=2.1.1
ECShop EPShop=2.1.1-a
ECShop EPShop=2.1.0
ECShop EPShop=2.1.2-b
ECShop EPShop=2.0.0
ECShop EPShop<=2.1.5
ECShop EPShop=2.0.1
ECShop EPShop=2.0.5
ECShop EPShop=2.0.3
ECShop EPShop=2.1.2
ECShop EPShop=2.1.2-a
ECShop EPShop=2.1.1-b
Event History
Jul 31, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3412?
CVE-2008-3412 has a moderate severity level as it allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2008-3412?
To fix CVE-2008-3412, update your Comsenz EPShop software to version 3.0 or later.
3
Which versions are affected by CVE-2008-3412?
CVE-2008-3412 affects Comsenz EPShop versions prior to 3.0, including 2.1.1, 2.0.2, and earlier releases.
4
What type of attack does CVE-2008-3412 enable?
CVE-2008-3412 enables SQL injection attacks, which can lead to unauthorized data access and manipulation.
5
Is CVE-2008-3412 easy to exploit?
Yes, CVE-2008-3412 can be easily exploited by providing specially crafted input through the pid parameter.