Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
References
Configurations
History
21 Nov 2024, 00:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://aria-security.net/advisory/eShopping.txt - Broken Link | |
References | () http://marc.info/?l=bugtraq&m=116353137028066&w=2 - Mailing List | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30262 - |
Information
Published : 2006-11-24 17:07
Updated : 2024-11-21 00:21
NVD link : CVE-2006-6073
Mitre link : CVE-2006-6073
CVE.ORG link : CVE-2006-6073
JSON object : View
Products Affected
enthrallweb
- eshopping_cart
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')