Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ProductCart Ecommerce 多个SQL注入漏洞
Vulnerability Description
ProductCart Ecommerce 2.7之前的版本中存在多个SQL注入漏洞,远程攻击者可借助:(1)提交到viewPrd.asp脚本的idcategory参数,(2)到editCategories.asp脚本的lid参数,(3)到modCustomCardPaymentOpt.asp脚本的icd参数,或(4)到OptionFieldsEdit.asp脚本的idccr参数,来执行任意SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A