CVE-2016-3694 | eCommerce Shopsoftware 2.0.0.0 rev 9678 easybillcsv.php customers_status/customers_status sql injection (EDB-39710)
A vulnerability classified as critical has been found in eCommerce Shopsoftware 2.0.0.0 rev 9678. Affected is an unknown function of the file api/easybill/easybillcsv.php. The manipulation of the argument customers_status/customers_status leads to sql injection.
This vulnerability is traded as CVE-2016-3694. It is possible to launch the attack remotely. Furthermore, there is an exploit available.