SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/3133 | vdb entry |
http://www.packetstormsecurity.org/0607-exploits/geoauctionsSQL.txt | exploit |
http://secunia.com/advisories/21325 | third party advisory |
http://www.securityfocus.com/bid/19093 | vdb entry exploit |