CVE-2003-1268

Publication date

2005-11-16 07:37:00

Family

mitre

State

PUBLISHED

Description

Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.