Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
References
Link | Resource |
---|---|
http://digitalparadox.org/viewadvisories.ah?view=42 | Exploit Vendor Advisory |
http://securitytracker.com/id?1014418 | Exploit Vendor Advisory |
http://digitalparadox.org/viewadvisories.ah?view=42 | Exploit Vendor Advisory |
http://securitytracker.com/id?1014418 | Exploit Vendor Advisory |
Configurations
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://digitalparadox.org/viewadvisories.ah?view=42 - Exploit, Vendor Advisory | |
References | () http://securitytracker.com/id?1014418 - Exploit, Vendor Advisory |
Information
Published : 2005-07-11 04:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2206
Mitre link : CVE-2005-2206
CVE.ORG link : CVE-2005-2206
JSON object : View
Products Affected
elemental_software
- cartwiz
CWE