Back
CVE-2005-2601
SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.
Published: Aug 17, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| midicart_software | midicart_php_shopping_cart | * |
GitHub Security Advisory GHSA-f62r-m64p-2wcj
SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands...
References (6)
- http://securitytracker.com/id?1014660 Exploit, Vendor Advisory
- http://systemsecure.org/ssforum/viewtopic.php?t=30 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/14544
- http://securitytracker.com/id?1014660 Exploit, Vendor Advisory
- http://systemsecure.org/ssforum/viewtopic.php?t=30 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/14544
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.32%
Top 31% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub