CVE-2010-0956: SQL Injection
Published Mar 9, 2010
·Updated
SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
Affected Software
1 affected component
OpenCart OpenCart=1.3.2
Event History
Mar 9, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 10, 2010
Data Sourced
via NVD·08:14 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0956?
CVE-2010-0956 is considered a high severity vulnerability due to its ability to allow remote SQL injection attacks.
2
How do I fix CVE-2010-0956?
To fix CVE-2010-0956, you should upgrade to a version of OpenCart that is not affected by this vulnerability.
3
What type of attacks can be executed through CVE-2010-0956?
CVE-2010-0956 allows attackers to execute arbitrary SQL commands on the database via the page parameter.
4
Which version of OpenCart is affected by CVE-2010-0956?
CVE-2010-0956 specifically affects OpenCart version 1.3.2.
5
Can CVE-2010-0956 be exploited without authentication?
Yes, CVE-2010-0956 can be exploited by unauthenticated remote attackers.