Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-4458

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-4458
Last Modified 19 Aug 2009 01:20:01
Published 06 Oct 2008 08:31:08
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-4458

Summary

SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.

Vulnerable Systems

Application

  • E-php Scripts B2b Trading Marketplace Script


References

XF - tradingmarketplace-listings-sql-injection(44975)

BID - 31072

BUGTRAQ - 20080910 Re: E-Php B2B Trading Marketplace(cid) Remote SQL InjectionVulnerability

SECUNIA - 31795

MISC - http://packetstorm.linuxsecurity.com/0809-exploits/ephpb2b-sql.txt


Last Updated: 27 May 2016 10:48:30