Unrated severityNVD Advisory· Published Jul 30, 2008· Updated Apr 23, 2026
CVE-2008-3369
CVE-2008-3369
Description
SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
Affected products
6cpe:2.3:a:viart:viart_shop:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:viart:viart_shop:*:*:*:*:*:*:*:*range: <=3.5
- cpe:2.3:a:viart:viart_shop:2.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:viart:viart_shop:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:viart:viart_shop:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:viart:viart_shop:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:viart:viart_shop:3.3:beta:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.viart.com/another_critical_sql_injection_security_fix_for_version_3_5.htmlnvdPatch
- www.gulftech.orgnvdExploit
- secunia.com/advisories/31275nvdVendor Advisory
- securityreason.com/securityalert/4065nvd
- www.securityfocus.com/archive/1/494839/100/0/threadednvd
- www.securityfocus.com/bid/30409nvd
- www.vupen.com/english/advisories/2008/2205/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44045nvd
- www.exploit-db.com/exploits/6154nvd
News mentions
0No linked articles in our index yet.