peter bassill · operator
$ cve CVE-2005-1487 JSON

CVE-2005-1487 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.45% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2005-05-11
Last modified2026-06-16

Affected (1)

VendorProduct
fishnetfishcart

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD