Back to search
CVE-2005-2621
Published: Aug 19, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
index.php in ECW-Shop 6.0.2 allows remote attackers to obtain sensitive information via the (1) min or (2) max parameter with a "'" (single quote), which reveals the path in an error message, possibly due to a SQL injection vulnerability.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20050815 [NOBYTES.COM: #9] ECW Shop 6.0.2 - Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
1014734
vdb-entry
x_refsource_SECTRACK
16459
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now