CVE-2010-4903: SQL Injection
Published Oct 8, 2011
·Updated
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
Affected Software
1 affected component
Cubecart CubeCart=4.3.3
Event History
Oct 8, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4903?
CVE-2010-4903 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2010-4903?
To fix CVE-2010-4903, upgrade your CubeCart installation to a version later than 4.3.3 which addresses this vulnerability.
3
What categories of impact does CVE-2010-4903 have?
CVE-2010-4903 can lead to unauthorized data access and manipulation through arbitrary SQL commands.
4
Who is affected by CVE-2010-4903?
CVE-2010-4903 affects users running CubeCart version 4.3.3.
5
What kind of attacks can be conducted using CVE-2010-4903?
Attackers can exploit CVE-2010-4903 to perform unauthorized SQL queries, which can compromise database integrity.