First published: Mon Apr 18 2005(Updated: )
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JD Edwards OneWorld |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1161 is classified as a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-1161, ensure proper input validation and sanitization for the idProduct, idCategory, and bSpecials parameters.
CVE-2005-1161 allows attackers to conduct SQL injection attacks, potentially retrieving or manipulating database information.
CVE-2005-1161 affects all versions of OneWorldStore as specified in the vulnerability report.
CVE-2005-1161 involves SQL injection vulnerabilities through the idProduct, idCategory, and bSpecials parameters.