osCommerce 4 POST Parameter shopping-cart estimate[country_id] SQL Injection
Hakika vulnerability da aka rarraba a matsayin kura an gano a osCommerce 4. Tabbas, aikin $software_function ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil /b2b-supermarket/shopping-cart, a cikin sashi POST Parameter Handler. Wuro manipulation of the argument estimate[country_id] ga SQL Injection. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-89. Lalle, rauni an sanar da shi 12/07/2023 da 176124. Ana samun bayanin tsaro don saukewa a packetstormsecurity.com. Ana kiran wannan rauni da CVE-2023-6579. Ngam yiɗi ka a tuma ndiyam ka internet. Bayani na fasaha ga. Kuma, akwai exploit. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á yí huɗɗi-na-gaskiya. 0-day ga, an ndiyam a wuro be $0-$5k. If you want to get best quality of vulnerability data, you may have to visit VulDB.
3 Goyarwa · 72 Datenpunkte