CVE-2010-1327

Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tornadostore:tornadostore:*:*:*:*:*:*:*:*

Information

Published : 2010-07-06 17:17

Updated : 2017-08-17 01:32


NVD link : CVE-2010-1327

Mitre link : CVE-2010-1327


JSON object : View

Products Affected

tornadostore

  • tornadostore
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')