CVE

Id
13396  
CVE No.
CVE-2005-2190  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.  
Phase
Assigned (20050710)  
Votes
None (candidate not yet proposed)  
Comments