HIGH
Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp
Published Jul 12, 2005
7.5
HIGHCVSS 2.0
EPSS 1.14%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.