First published: Mon Dec 28 2009(Updated: )
SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.flypage action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirtueMart Joomla Ecommerce Edition CMS | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4430 has a medium severity rating due to its potential for SQL injection attacks.
To fix CVE-2009-4430, it is recommended to upgrade to a version of VirtueMart that does not contain this vulnerability.
CVE-2009-4430 specifically affects VirtueMart version 1.0.
CVE-2009-4430 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
Attackers can exploit CVE-2009-4430 by injecting malicious SQL code through the product_id parameter in the shop.product_details or shop.flypage actions.