Multiple SQL injection vulnerabilities in Infinitytechs Restaurants CM allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in rating.asp, (2) the mealid parameter in meal_rest.asp, and (3) the resid parameter in res_details.asp.
Link | Tags |
---|---|
http://securityreason.com/securityalert/1981 | third party advisory |
http://www.securityfocus.com/archive/1/451970/100/200/threaded | mailing list |