CVE

Id
26604  
CVE No.
CVE-2007-3247  
Status
Candidate  
Description
SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.  
Phase
Assigned (20070618)  
Votes
None (candidate not yet proposed)  
Comments