Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/23507 | vdb entry |
http://www.securityfocus.com/bid/15699/ | vdb entry exploit |
http://www.osvdb.org/21622 | vdb entry |
http://securityreason.com/securityalert/228 | third party advisory |
http://www.securityfocus.com/archive/1/418510/100/0/threaded | mailing list |