CVE-2008-3788 Information

Description

Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9 when magic_quotes_gpc is disabled allow remote attackers to execute arbitrary SQL commands via the (1) qtitle (2) qid and (3) qyear parameters to (a) search.php and the (4) email and (5) password parameters to (b) _login.php.

Reference

http://packetstormsecurity.org/0808-exploits/photocart-sql.txt http://securityreason.com/securityalert/4188 http://www.securityfocus.com/bid/30786 https://exchange.xforce.ibmcloud.com/vulnerabilities/44607 https://www.exploit-db.com/exploits/6285

Share on: