CVE Vulnerabilities

CVE-2006-1098

Published: Mar 09, 2006 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researchers blog, but research by CVE suggests that this might be a legitimate problem

Affected Software

Name Vendor Start Version End Version
Nz_ecommerce Digital_builder * *

References