SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/34953 | vdb entry |
http://www.securityfocus.com/archive/1/471837/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/24562 | vdb entry exploit |
http://securityreason.com/securityalert/2819 | third party advisory |
http://osvdb.org/36152 | vdb entry |