CVE-2006-6073

Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:enthrallweb:eshopping_cart:-:*:*:*:*:*:*:*

Information

Published : 2006-11-24 09:07

Updated : 2017-07-19 18:34


NVD link : CVE-2006-6073

Mitre link : CVE-2006-6073


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

enthrallweb

  • eshopping_cart