8 lines
No EOL
733 B
Text
8 lines
No EOL
733 B
Text
source: https://www.securityfocus.com/bid/13384/info
|
|
|
|
A remote SQL injection vulnerability affects MetaCart2. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.
|
|
|
|
An attacker may exploit this issue to manipulate SQL queries to the underlying database. This may facilitate theft sensitive information, potentially including authentication credentials, and data corruption.
|
|
|
|
http://www.example.com/mcart2pfp/productsByCategory.asp?strSubCatalogID=1&%3bcurCatalogID='SQL_INJECTION&%3bstrSubCatalog_NAME=Laptops
|
|
http://www.example.com/mcart2pal/productsByCategory.asp?strSubCatalogID=1&%3bcurCatalogID=%27SQL_INJECTION&%3bstrSubCatalog_NAME=Laptops |