CVE-2010-1327

Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tornadostore:tornadostore:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:14

Type Values Removed Values Added
References () http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-sql-injection-0106.php - Exploit () http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-sql-injection-0106.php - Exploit
References () http://www.securityfocus.com/bid/41233 - Exploit () http://www.securityfocus.com/bid/41233 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/59950 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/59950 -

Information

Published : 2010-07-06 17:17

Updated : 2025-04-11 00:51


NVD link : CVE-2010-1327

Mitre link : CVE-2010-1327

CVE.ORG link : CVE-2010-1327


JSON object : View

Products Affected

tornadostore

  • tornadostore
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')