SQL Injection Vulnerability in CS-Cart by CS-Cart Technologies
CVE-2008-6394

Currently unrated

Key Information:

Vendor

Cs-cart

Status
Vendor
CVE Published:
4 March 2009

What is CVE-2008-6394?

A SQL injection vulnerability exists in the core/user.php file of CS-Cart versions 1.3.5 and earlier. This flaw allows remote attackers to manipulate SQL queries by injecting arbitrary SQL code through the 'cs_cookies[customer_user_id]' cookie parameter. As a result, unauthorized users may obtain sensitive information from the database or execute harmful commands, potentially leading to a complete compromise of the system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.