CVE-2006-5962

Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hpecs_shopping_cart:hpecs_shopping_cart:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:21

Type Values Removed Values Added
References () http://secunia.com/advisories/22904 - Vendor Advisory () http://secunia.com/advisories/22904 - Vendor Advisory
References () http://securityreason.com/securityalert/1879 - () http://securityreason.com/securityalert/1879 -
References () http://www.securityfocus.com/archive/1/451595/100/0/threaded - () http://www.securityfocus.com/archive/1/451595/100/0/threaded -
References () http://www.vupen.com/english/advisories/2006/4535 - () http://www.vupen.com/english/advisories/2006/4535 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30287 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30287 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30288 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30288 -
References () https://www.exploit-db.com/exploits/2782 - () https://www.exploit-db.com/exploits/2782 -

Information

Published : 2006-11-17 01:07

Updated : 2025-04-09 00:30


NVD link : CVE-2006-5962

Mitre link : CVE-2006-5962

CVE.ORG link : CVE-2006-5962


JSON object : View

Products Affected

hpecs_shopping_cart

  • hpecs_shopping_cart