Vulnonym.org

CVE-2004-2561 - Airborne Piles

Description

Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.

Reference

http://www.securiteam.com/windowsntfocus/5RP0N0ADGK.html http://www.securityfocus.com/bid/10771 http://www.osvdb.org/8180 http://secunia.com/advisories/12121 https://exchange.xforce.ibmcloud.com/vulnerabilities/16775