Comersus Open Technologies Comersus Cart Multiple SQL Injection Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/comersus6/store/comersus_optAffiliateRegistrationExec.asp?name=1&email='&Submit=Join%20now%21
http://www.example.com/comersus6/store/comersus_optReviewReadExec.asp?idProduct='&description=


 

Privacy Statement
Copyright 2010, SecurityFocus