Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2038


Vulnerability Score 6.5 6.5
CVE Id CVE-2008-2038
Last Modified 05 Nov 2008 01:38:01
Published 30 Apr 2008 12:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE



Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Systems


  • Turnkey Solutions Sunshop Shopping Cart 4.1.0


XF - sunshop-adminindex-sql-injection(41882)

BID - 28832

SECUNIA - 29811

Last Updated: 27 May 2016 10:47:44