|
Description
|
|
Two vulnerabilities were identified in VP-ASP Shopping Cart, which may be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in "shopaddtocart.asp", "shopproductselect.asp" and "shopaddtocartnodb.asp" when processing a specially crafted "productid" or "catalogid" parameter, which may be exploited by remote users to conduct SQL injection attacks.
|