CVE Vulnerabilities

CVE-2001-0319

Published: May 03, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.

Affected Software

Name Vendor Start Version End Version
Net.commerce Ibm 2.0 (including) 2.0 (including)
Net.commerce Ibm 3.0 (including) 3.0 (including)
Net.commerce Ibm 3.1 (including) 3.1 (including)
Net.commerce Ibm 3.1.1 (including) 3.1.1 (including)
Net.commerce Ibm 3.1.2 (including) 3.1.2 (including)
Net.commerce Ibm 3.2 (including) 3.2 (including)
Net.commerce_hosting_server Ibm 3.1.1 (including) 3.1.1 (including)
Net.commerce_hosting_server Ibm 3.1.2 (including) 3.1.2 (including)
Net.commerce_hosting_server Ibm 3.2 (including) 3.2 (including)
Websphere_commerce_suite Ibm 3.1.2 (including) 3.1.2 (including)
Websphere_commerce_suite Ibm 3.2 (including) 3.2 (including)
Websphere_commerce_suite Ibm 4.1 (including) 4.1 (including)
Websphere_commerce_suite Ibm 4.1.1 (including) 4.1.1 (including)

References