SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Digitizing_quote_and_ordering_system | Digitizing_quote_and_ordering_system | 1.0 (including) | 1.0 (including) |