CVE-2007-3175 Information

Description

Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b.

Reference

http://osvdb.org/37466 http://osvdb.org/37467 http://pridels-team.blogspot.com/2007/05/w2b-online-banking-vuln.html https://exchange.xforce.ibmcloud.com/vulnerabilities/34593

Share on: