Multiple SQL injection vulnerabilities in SitesOutlet E-commerce Kit-1 PayPal Edition allow remote attackers to execute arbitrary SQL commands via the (1) keyword or (2) cid parameter in (a) catalogue.asp, or the (3) pid parameter in (b) viewDetail.asp.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/21056 | vdb entry |
http://securityreason.com/securityalert/1900 | third party advisory |
http://secunia.com/advisories/22975 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/4571 | vdb entry |
http://www.securityfocus.com/archive/1/451771/100/0/threaded | mailing list |