Security Advisory

CVE-2010-4632

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-12-30 20:00:00
Last updated 2024-09-17 01:01:46
Assigner mitre
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL commands via the (1) article parameter to kb.asp, (2) specific parameter to cart.asp, (3) countrycode parameter to contact.asp, and the (4) srch parameter to search.asp. NOTE: the article parameter to pilot.asp is already covered by CVE-2008-2688.