CVE-2009-2579
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.
- Affected products
- Cs-Cart
- Cs-cart
- ≤ 2.0.5, 1.1, 1.2, 1.3.0, 1.3.2, 1.3.3, 1.3.5, 1.3.5sp2, 1.3.5sp3, 2.0, 2.0.4
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2009-08-05
CVE-2009-2579 at NVD
2 known exploits for CVE-2009-2579
Proof-of-concept code and exploit modules indexed by Sploitus