CVE-2006-6031 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Greater Cincinnati Internet Solutions (GCIS) ASPCart allow remote attackers to execute arbitrary SQL commands via (1) the prodid parameter in (a) prodetails.asp; (2) the page parameter in (b) display.asp; the (3) custid (4) item (5) price (6) custom (7) department (8) start (9) quantity (10) submit (11) custom1 (12) custom2 or (13) custom3 parameters in (c) addcart.asp; or the (14) customerid parameter in (d) payment.asp.
Reference
http://secunia.com/advisories/22946 http://securityreason.com/securityalert/1899 http://www.securityfocus.com/archive/1/451858/100/0/threaded http://www.securityfocus.com/bid/21152 http://www.vupen.com/english/advisories/2006/4580
Share on: