CVE-2005-3914 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
Reference
http://pridels0.blogspot.com/2005/11/affcommerce-multiple-sql-inj.html http://secunia.com/advisories/17690 http://www.osvdb.org/21070 http://www.osvdb.org/21071 http://www.osvdb.org/21072 http://www.securityfocus.com/bid/15545 http://www.vupen.com/english/advisories/2005/2550
Share on: