CVE

Id
17202  
CVE No.
CVE-2006-1098  
Status
Candidate  
Description
** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher"s blog, but research by CVE suggests that this might be a legitimate problem.  
Phase
Assigned (20060309)  
Votes
None (candidate not yet proposed)  
Comments