CVE-2017-15975

Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vastal:dating_zone:0.9.9:*:*:*:*:*:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/144445/Vastal-I-Tech-Dating-Zone-0.9.9-SQL-Injection.html - Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/144445/Vastal-I-Tech-Dating-Zone-0.9.9-SQL-Injection.html - Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/43084/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/43084/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-10-29 06:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-15975

Mitre link : CVE-2017-15975

CVE.ORG link : CVE-2017-15975


JSON object : View

Products Affected

vastal

  • dating_zone
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')