CVE-2008-6277 Information

Description

SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.

Reference

http://packetstormsecurity.com/0811-exploits/rakhi-sqlxssfpd.txt http://secunia.com/advisories/32897 http://www.osvdb.org/50313 https://exchange.xforce.ibmcloud.com/vulnerabilities/46920 https://www.exploit-db.com/exploits/7250

Share on: