Sploitus

CVE-2009-2579

2 known exploits for CVE-2009-2579

SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.

Affected products
Cs-Cart
Cs-cart
≤ 2.0.5, 1.1, 1.2, 1.3.0, 1.3.2, 1.3.3, 1.3.5, 1.3.5sp2, 1.3.5sp3, 2.0, 2.0.4
Fix
Available
CVSS 2.0
6.5 MEDIUM
EPSS
0.9% (56th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2009-08-05
CVE-2009-2579 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2009-2579

Proof-of-concept code and exploit modules indexed by Sploitus