Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
| Software | From | Fixed in |
|---|---|---|
| early_impact / productcart | 1.5003r | 1.5003r.x |
| early_impact / productcart | 1.6002 | 1.6002.x |
| early_impact / productcart | 1.6b001 | 1.6b001.x |
| early_impact / productcart | 1.6br001 | 1.6br001.x |
| early_impact / productcart | 1.6b003 | 1.6b003.x |
| early_impact / productcart | 1.5 | 1.5.x |
| early_impact / productcart | 1.5004 | 1.5004.x |
| early_impact / productcart | 1.5002 | 1.5002.x |
| early_impact / productcart | 2br000 | 2br000.x |
| early_impact / productcart | 1.5003 | 1.5003.x |
| early_impact / productcart | 1.6br | 1.6br.x |
| early_impact / productcart | 1.6br003 | 1.6br003.x |
| early_impact / productcart | 2 | 2.x |
| early_impact / productcart | 1.6003 | 1.6003.x |
| early_impact / productcart | 1.6b | 1.6b.x |
| early_impact / productcart | 1.6b002 | 1.6b002.x |