CVE-2006-5962
HIGH 7.5EPSS 1.3%
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 1.32% chance of exploitation in the next 30 days, 69th percentile
- Published
- 2006-11-17
- Updated
- 2024-08-07