CVE-2005-1487 describes multiple SQL injection vulnerabilities in FishCart 3.1, specifically affecting the 'cartid' parameter in upstnt.php and the 'psku' parameter in display.php. This vulnerability carries a CVSS score of 7.5, indicating a high severity with a network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While the vendor disputes the report and the original researcher's reliability is questioned, exploit code for both injection points is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, it is not listed on the KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1CPE matchmatch criteria | cpe:2.3:a:fishnet:fishcart:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.