Web4Future eCommerce Enterprise Edition Multiple SQL Injection Vulnerabilities

No exploit is required.

Example URI have been provided:
http://www.example.com/view.php?prod=[SQL]
http://www.example.com/viewbrands.php?bid=[SQL]
http://www.example.com/view.php?prod=1010001&brid=[SQL]
http://www.example.com/index.php?action=ViewGroups&grp=[SQL]
http://www.example.com/index.php?action=ViewCategories&cat=[SQL]


 

Privacy Statement
Copyright 2010, SecurityFocus