CVE

Id
12367  
CVE No.
CVE-2005-1161  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.  
Phase
Assigned (20050418)  
Votes
None (candidate not yet proposed)  
Comments