Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-11-26T22:00:00

Updated: 2017-07-19T15:57:01

Reserved: 2006-11-26T00:00:00


Link: CVE-2006-6109

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-11-26T22:07:00.000

Modified: 2024-02-14T01:17:43.863


Link: CVE-2006-6109

JSON object: View

cve-icon Redhat Information

No data.

CWE