Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ShopWeezle Multiple SQL Injection Vulnerabilities

This issue can be exploited through a web client.

The following example URIs are available to demonstrate these issues:

http://www.example.com/login.php?caller=xlink&url=detail.php&itemID=1[SQL]
http://www.example.com/index.php?x=0&itemgr=1[SQL]
http://www.example.com/index.php?caller=xlink&url=brand.php&brandID=1[SQL]
http://www.example.com/memo.php?itemID=1[SQL]
http://www.example.com/index.php?x=0&caller=xlink&url=gallery.php&album=1[SQL]







 

Privacy Statement
Copyright 2009, SecurityFocus