Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Metacart_e-shop | Metalinks | 8.0 (including) | 8.0 (including) |