CVE-2010-1327

Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tornadostore:tornadostore:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-07-06 17:17

Updated : 2024-02-04 17:54


NVD link : CVE-2010-1327

Mitre link : CVE-2010-1327

CVE.ORG link : CVE-2010-1327


JSON object : View

Products Affected

tornadostore

  • tornadostore
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')