SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Media2_cms_shop | Media2_cms | * | 18.2 (including) |