HIGH
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp
Published Feb 13, 2008
7.5
HIGHCVSS 2.0
EPSS 0.96%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.