CVE-2014-10033: SQL Injection
Published Jan 13, 2015
·Updated
SQL injection vulnerability in the updatezone function in catalog/admin/geozones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
Affected Software
1 affected component
osCommerce Online Merchant<=2.3.3.4
Event History
Jan 13, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-10033?
CVE-2014-10033 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2014-10033?
To fix CVE-2014-10033, update to osCommerce Online Merchant version 2.3.4 or later.
3
What are the potential implications of CVE-2014-10033?
Exploiting CVE-2014-10033 allows remote administrators to execute arbitrary SQL commands, potentially compromising the database.
4
Can CVE-2014-10033 be exploited by unauthenticated users?
No, CVE-2014-10033 requires administrative access to exploit the vulnerability.
5
Which versions of osCommerce are affected by CVE-2014-10033?
osCommerce Online Merchant versions 2.3.3.4 and earlier are affected by CVE-2014-10033.