Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Brooky CubeCart < 2.0.2 index.php cat_id Parameter SQL Injection



The remote web server contains a script that is vulnerable to a SQL injection attack.


The remote host is using Brooky CubeCart, an online storefront application written in PHP. A vulnerability exists in the remote version of this product that may allow a remote attacker to perform a SQL injection attack against the remote host. An attacker may exploit this flaw to execute arbitrary SQL statements against the remote database and possibly execute arbitrary commands on the remote host.


Upgrade to Brooky CubeCart 2.0.2 or higher.