Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
References
Link | Resource |
---|---|
http://digitalparadox.org/viewadvisories.ah?view=42 | Exploit Vendor Advisory |
http://securitytracker.com/id?1014418 | Exploit Vendor Advisory |
Configurations
Information
Published : 2005-07-10 21:00
Updated : 2008-09-05 13:51
NVD link : CVE-2005-2206
Mitre link : CVE-2005-2206
JSON object : View
CWE
Products Affected
elemental_software
- cartwiz