PoC Index

CVE-2008-0546

HIGH 7.5EPSS 3.1%

Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.15% chance of exploitation in the next 30 days, 87th percentile
Published
2008-02-01
Updated
2024-08-07

ExploitDB entries (1)

References

Related