Unrated severityNVD Advisory· Published Aug 11, 2008· Updated Apr 23, 2026
CVE-2008-3594
CVE-2008-3594
Description
SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Affected products
4cpe:2.3:a:magicscripts:e-store_kit-1:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:magicscripts:e-store_kit-1:*:*:*:*:*:*:*:*
- cpe:2.3:a:magicscripts:e-store_kit-1:*:*:pro_paypal:*:*:*:*:*
cpe:2.3:a:magicscripts:e-store_kit-2:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:magicscripts:e-store_kit-2:*:*:*:*:*:*:*:*
- cpe:2.3:a:magicscripts:e-store_kit-2:*:*:paypal:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.