Description
|
|
Multiple vulnerabilities were identified in MetaCart and MetaCart2, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to an input validation error in the "product.asp", "productsByCategory.asp" and "searchAction.asp" scripts when handling specially crafted "intProdID", "intCatalogID", "strSubCatalogID", "curCatalogID", "strSubCatalog_NAME", "chkText", "strText", "chkPrice", "intPrice", "chkCat", and "strCat" parameters, which may be exploited by remote users to conduct SQL injection attacks.
|