Mega Mall CVE-2006-7170 SQL-Injection Vulnerability

Mega Mall is prone to a sql-injection vulnerability. Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.


 

Privacy Statement
Copyright 2010, SecurityFocus