Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
Link | Tags |
---|---|
http://securitytracker.com/id?1013720 | vdb entry exploit |
http://www.securityfocus.com/bid/13183 | patch vdb entry exploit |
http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab | url repurposed |
http://www.securityfocus.com/bid/13182 | patch vdb entry exploit |
http://www.osvdb.org/15518 | vdb entry |
http://www.osvdb.org/15520 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20097 | vdb entry |
http://www.securityfocus.com/bid/13181 | patch vdb entry exploit |
http://www.osvdb.org/15519 | vdb entry |
http://marc.info/?l=bugtraq&m=111352017704126&w=2 | mailing list |
http://secunia.com/advisories/14969 | third party advisory patch |