SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cactushop | Cactusoft | 5.0 (including) | 5.0 (including) |
| Cactushop | Cactusoft | 5.1 (including) | 5.1 (including) |