Security Advisory

CVE-2005-2477

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-08-05 04:00:00
Last updated 2024-08-07 22:29:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.