First published: Thu Mar 05 2009(Updated: )
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-cart | =1.3 | |
Jenkins |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0832 has a moderate severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2009-0832, sanitize all user inputs and update the E-Cart module to a version that does not contain this vulnerability.
CVE-2009-0832 specifically affects the E-Cart module version 1.3 for PHP-Fusion.
Yes, CVE-2009-0832 can be exploited remotely, allowing attackers to execute SQL commands through the vulnerable parameter.
Web application attackers can use CVE-2009-0832 for SQL injection attacks to manipulate or access the database unlawfully.