CVE-2005-4035 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
Reference
http://pridels0.blogspot.com/2005/12/ecommerce-enterprise-edition-sql-inj.html http://secunia.com/advisories/17881 http://www.osvdb.org/21466 http://www.osvdb.org/21467 http://www.osvdb.org/21468 http://www.securityfocus.com/bid/15707 http://www.vupen.com/english/advisories/2005/2744
Share on: