Описание
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
Ссылки
- Patch
- Exploit
- URL Repurposed
- ExploitPatch
- ExploitPatch
- ExploitPatch
- Patch
- Exploit
- URL Repurposed
- ExploitPatch
- ExploitPatch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oneworldstore:oneworldstore:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03589
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
EPSS
Процентиль: 88%
0.03589
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other