CVE-2010-2460 Information

Description

SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.

Reference

http://www.exploit-db.com/exploits/13949 http://www.securityfocus.com/bid/40993 https://exchange.xforce.ibmcloud.com/vulnerabilities/59581

Share on: