lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20061114181845.31312.qmail@securityfocus.com> Date: 14 Nov 2006 18:18:45 -0000 From: saps.audit@...il.com To: bugtraq@...urityfocus.com Subject: MetaCart e-Shop [multiples injection sql (get & post)] vendor site:http://metalinks.com/ product:MetaCart e-Shop bug:injection sql risk:medium injection sql (get) : http://site.com/metacart/productsByCategory.asp?intCatalogID='[sql] http://site.com/metacart/product.asp?intProdID='[sql] injection sql(post) : 1 )http://site.com/metacart/searchAction.asp variables : /metacart/searchAction.asp?chkText=yes&strText='[sql] 2)http://site.com/metacart/searchAction.asp variables : /metacart/searchAction.asp?chkText=yes&strText=1&chkPrice=yes&chkCat=yes&sub mit1=Submit&intPrice='[sql] 3)http://site.com/metacart/searchAction.asp variables : /metacart/searchAction.asp?chkText=yes&strText=1&chkPrice=yes&chkCat=yes&sub mit1=Submit&intPrice=all&strCat='[sql] laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@...il.com