Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Online_banking | W2b | * | * |