SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  OpenCart SQL Injection

Category: WEB-ATTACKS      

An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. As an anonymous unauthenticated user, if the Divido payment module is installed (it does not have to be enabled), it is possible to exploit SQL injection to gain unauthorised access to the backend database. This signature detects SQL commands sent in HTTP requests. These are generally considered suspicious.


Relevant Information