CVE-2008-0719 Information

Description

SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.

Reference

http://secunia.com/advisories/28831 http://www.securityfocus.com/bid/27664 https://www.exploit-db.com/exploits/5075

Share on: