CVE

Id
7336  
CVE No.
CVE-2003-0509  
Status
Candidate  
Description
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.  
Phase
Assigned (20030703)  
Votes
None (candidate not yet proposed)  
Comments