CVE-2010-1931: SQL Injection
Published Jun 10, 2010
·Updated
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.
Affected Software
6 affected components
Cubecart CubeCart=4.3.9
Cubecart CubeCart=4.3.4
Cubecart CubeCart=4.3.5
Cubecart CubeCart=4.3.6
Cubecart CubeCart=4.3.7
Cubecart CubeCart=4.3.8
Remediation
Patch Available
Event History
Jun 10, 2010
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:30 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1931?
CVE-2010-1931 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2010-1931?
To fix CVE-2010-1931, upgrade CubeCart to version 4.3.10 or later.
3
Which versions of CubeCart are affected by CVE-2010-1931?
CubeCart versions 4.3.4 to 4.3.9 are affected by CVE-2010-1931.
4
What type of vulnerability is CVE-2010-1931?
CVE-2010-1931 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Where can CVE-2010-1931 be exploited?
CVE-2010-1931 can be exploited through the shipKey parameter in the index.php file of CubeCart.