Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the OrderID parameter in (a) shipping.cfm and (b) checkout.cfm, (2) ItemID parameter in (c) proddetail.cfm, (3) SubCatID parameter in (d) index.cfm, the (4) CategoryID parameter in (e) prodpage.cfm, and (5) ProdID parameter in (f) Details.cfm. NOTE: these issues can also be exploited for path disclosure.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-04-26T20:00:00
Updated: 2024-08-07T17:35:31.273Z
Reserved: 2006-04-26T00:00:00
Link: CVE-2006-2053

No data.

Status : Modified
Published: 2006-04-26T20:06:00.000
Modified: 2024-11-21T00:10:26.773
Link: CVE-2006-2053

No data.