AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.
                
            References
                    | Link | Resource | 
|---|---|
| https://demo.ripstech.com/projects/abantecart_1.2.8 | Third Party Advisory | 
| https://blog.ripstech.com/2016/abantecart-multiple-sql-injections/ | Third Party Advisory | 
Configurations
                    Information
                Published : 2019-05-24 11:29
Updated : 2019-05-29 07:58
NVD link : CVE-2016-10755
Mitre link : CVE-2016-10755
JSON object : View
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
                abantecart
- abantecart
 


