SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters.
References
Configurations
History
21 Nov 2024, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/38555 - | |
References | () http://securityreason.com/securityalert/3189 - | |
References | () http://www.securityfocus.com/archive/1/481211/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/25884 - Exploit | |
References | () http://www.vupen.com/english/advisories/2007/3345 - |
Information
Published : 2007-10-05 00:17
Updated : 2024-11-21 00:37
NVD link : CVE-2007-5220
Mitre link : CVE-2007-5220
CVE.ORG link : CVE-2007-5220
JSON object : View
Products Affected
asp_product_catalog
- asp_product_catalog
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')