Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.
Link | Tags |
---|---|
http://secunia.com/advisories/12121 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/10771 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16775 | vdb entry |
http://www.osvdb.org/8180 | vdb entry exploit |
http://www.securiteam.com/windowsntfocus/5RP0N0ADGK.html | vendor advisory exploit |