Security Advisory

CVE-2007-4597

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-08-30 17:00:00
Last updated 2024-08-07 15:01:09
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.