CVE-2005-1362

Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or (9) strCat parameters to searchAction.asp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:metalinks:metacart2:paypal:*:*:*:*:*:*:*

History

20 Nov 2024, 23:57

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=111454090503662&w=2 - () http://marc.info/?l=bugtraq&m=111454090503662&w=2 -

Information

Published : 2005-05-02 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2005-1362

Mitre link : CVE-2005-1362

CVE.ORG link : CVE-2005-1362


JSON object : View

Products Affected

metalinks

  • metacart2