Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
References
Link | Resource |
---|---|
http://digitalparadox.org/viewadvisories.ah?view=42 | Exploit Vendor Advisory |
http://securitytracker.com/id?1014418 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2005-07-11 04:00
Updated : 2024-02-28 10:42
NVD link : CVE-2005-2206
Mitre link : CVE-2005-2206
CVE.ORG link : CVE-2005-2206
JSON object : View
Products Affected
elemental_software
- cartwiz
CWE