Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2038

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2008-2038
Last Modified 05 Nov 2008 01:38:01
Published 30 Apr 2008 12:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2008-2038

Summary

Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Systems

Application

  • Turnkey Solutions Sunshop Shopping Cart 4.1.0


References

XF - sunshop-adminindex-sql-injection(41882)

BID - 28832

SECUNIA - 29811


Last Updated: 27 May 2016 10:47:44