CVE-2005-4081 Information

Description

Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.

Reference

http://securityreason.com/securityalert/228 http://www.osvdb.org/21622 http://www.securityfocus.com/archive/1/418510/100/0/threaded http://www.securityfocus.com/bid/15699/ https://exchange.xforce.ibmcloud.com/vulnerabilities/23507

Share on: