CVE-2010-1327

Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:tornadostore:tornadostore:*:*:*:*:*:*:*:*

Information

Published : 2010-07-06 10:17

Updated : 2017-08-16 18:32


NVD link : CVE-2010-1327

Mitre link : CVE-2010-1327


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

tornadostore

  • tornadostore