Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6466 (FreeWebShop)

BugsAlert Home > CVE-2007-6466 (FreeWebShop)
 
 

Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6466

Learn more about CVE-2007-6466 (FreeWebShop)
 
Tags: cve-2007-6466 freewebshop

Related Items

      FrSIRT - eMule X-Ray Memory Corruption and Buffer Overflow Vulnerabilities

      Microsoft Security Advisory (960906): Vulnerability in WordPad Text Converter Could Allow Remote Code Execution - 12/9/2008

      CVE-2008-1157 (ciscoWorks_internetwork_performance_monitor)

      CVE-2008-5348 (jdk, jre, sdk)

      CVE-2008-3412 (epshop)

      HP-UX update for Apache

      rPath update for ruby

 

Pixel