HIGH
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp
Published Dec 1, 2006
7.5
HIGHCVSS 2.0
EPSS 1.39%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.