First published: Thu May 03 2001(Updated: )
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Net.Commerce | =3.1.2 | |
Ibm Net.commerce Hosting Server | =3.1.1 | |
IBM Net.Commerce | =3.1 | |
IBM Net.Commerce | =3.1.1 | |
IBM WebSphere Commerce Suite | =4.1 | |
IBM Net.Commerce | =3.2 | |
IBM WebSphere Commerce Suite | =4.1 | |
IBM Net.Commerce | =2.0 | |
IBM WebSphere Commerce Suite | =3.1.2 | |
IBM Net.Commerce | =3.0 | |
IBM Net.Commerce | =3.1.1 | |
IBM Net.Commerce | =3.2 | |
IBM WebSphere Commerce Suite | =4.1.1 | |
IBM WebSphere Commerce Suite | =3.2 | |
Ibm Net.commerce Hosting Server | =3.2 | |
IBM WebSphere Commerce Suite | =4.1.1 | |
Ibm Net.commerce Hosting Server | =3.1.2 | |
IBM WebSphere Commerce Suite | =4.1 | |
IBM Net.Commerce | =3.1 | |
IBM Net.Commerce | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.