Back

CVE-2004-0300

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Published: Nov 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
ecommerce_corporation_online store_kit 3.0_lite
ecommerce_corporation_online store_kit 3.0_pro
ecommerce_corporation_online store_kit 3.0_standard

GitHub Security Advisory GHSA-633w-j862-v7j8

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 5.17%

Top 8% most likely to be exploited

Threat Score 41.6 / 100

Data Sources

NVD EPSS GitHub