CVE-2009-2254: SQL Injection
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the querystring parameter in an execute action, in conjunction with a PATHINFO of passwordforgotten.php, related to a "SQL Execution" issue.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2009-2254?
CVE-2009-2254 is a vulnerability in Zen Cart versions 1.3.8a and earlier that allows unauthorized access to the admin/sqlpatch.php file, leading to potential SQL injection attacks.
What are the affected versions in CVE-2009-2254?
CVE-2009-2254 affects Zen Cart versions from 1.1.0 to 1.3.8a inclusive.
How do I fix CVE-2009-2254?
To fix CVE-2009-2254, upgrade your Zen Cart installation to version 1.3.9 or later.
What are the potential impacts of CVE-2009-2254?
The impacts of CVE-2009-2254 can include remote execution of arbitrary SQL commands and unauthorized access to sensitive database information.
Is CVE-2009-2254 a critical vulnerability?
Yes, CVE-2009-2254 is considered a critical vulnerability due to the potential for severe exploitation.