CVE-2006-6111

Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:alan_ward:a-cart:2.0:*:*:*:*:*:*:*
cpe:2.3:a:alan_ward:a-cart:2.0:*:pro:*:*:*:*:*

History

14 Feb 2024, 01:17

Type Values Removed Values Added
References () http://s-a-p.ca/index.php?page=OurAdvisories&id=27 - Exploit () http://s-a-p.ca/index.php?page=OurAdvisories&id=27 - Exploit, URL Repurposed

Information

Published : 2006-11-26 22:07

Updated : 2024-02-14 01:17


NVD link : CVE-2006-6111

Mitre link : CVE-2006-6111

CVE.ORG link : CVE-2006-6111


JSON object : View

Products Affected

alan_ward

  • a-cart