HTTP: osCommerce products_id Parameter SQL Injection

This signature detects attempts to exploit a known SQL injection vulnerability in a script supplied as part of the osCommerce product. Attackers can submit an HTTP request that contains a maliciously formed "products_id" parameter to create a denial-of-service (DoS)condition.

Extended Description

It has been reported that one of the scripts included with osCommerce fails to validate user-supplied input, rendering it vulnerable to a SQL injection attack. It has been reported that an attacker may supply malicious SQL queries as a URI parameter to the affected script. The attacker may leverage this condition to manipulate the logic and structure of database queries, possibly resulting in osCommerce compromise, information disclosure or other consequences.

Affected Products

Oscommerce oscommerce

Short Name
HTTP:SQL:INJ:OSCOM
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Injection Parameter SQL bid:9275 osCommerce products_id
Release Date
09/01/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Oscommerce

Found a potential security threat?