CVE-2004-2561 - Airborne Piles
Description
Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.
Reference
http://www.securiteam.com/windowsntfocus/5RP0N0ADGK.html http://www.securityfocus.com/bid/10771 http://www.osvdb.org/8180 http://secunia.com/advisories/12121 https://exchange.xforce.ibmcloud.com/vulnerabilities/16775