Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15794
HistoryJan 24, 2007 - 12:00 a.m.

FishCart [injection sql]

2007-01-2400:00:00
vulners.com
56

vendor site: http://fishcart.org/
product :fish cart
bug:injection sql
risk : medium

injection sql :
/display.php?cartid=200701210157208&zid=1&lid=1&olimit=5&cat=&key1=&nlst=y&olst='[sql]

( change the cartid value with yours )

laurent gaffie
http://s-a-p.ca/
contact: [email protected]