X-Cart Gold contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'productid' and 'mode' variables in the product.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
OSVDB:
Web Related
Solution
Upgrade to version 4.0.12 or higher, as it has been reported to fix this vulnerability. In addition, Qualiteam Corporation has released a patch for some older versions.