SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/34573 | vdb entry |
http://osvdb.org/38042 | vdb entry |
http://securityreason.com/securityalert/2747 | third party advisory |
http://www.securityfocus.com/bid/24223 | vdb entry exploit |
http://www.securityfocus.com/archive/1/469910/100/0/threaded | mailing list |