Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=105760660928715&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=105733145930031&w=2 | mailing list |