Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.
References
Configurations
Information
Published : 2006-05-11 03:02
Updated : 2017-07-19 18:31
NVD link : CVE-2006-2300
Mitre link : CVE-2006-2300
JSON object : View
CWE
Products Affected
keyvan1
- eimagepro