CVE-2010-2042: SQL Injection
Published May 25, 2010
·Updated
SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
shopex ecshop=2.7.2
Event History
May 25, 2010
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2042?
CVE-2010-2042 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How can I fix CVE-2010-2042?
To fix CVE-2010-2042, it is recommended to upgrade ECShop to the latest version that addresses this SQL injection vulnerability.
3
What software is affected by CVE-2010-2042?
CVE-2010-2042 affects ECShop version 2.7.2 specifically.
4
What type of vulnerability is CVE-2010-2042?
CVE-2010-2042 is an SQL injection vulnerability found in the search.php file of ECShop.
5
Can CVE-2010-2042 be exploited remotely?
Yes, CVE-2010-2042 can be exploited remotely by attackers who manipulate the encode parameter.