Record summary

CVE-2001-0319 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM Net.Commerce 2.0/3.x/4.x - orderdspc.d2w order_rn Option SQL InjectionExploitDB exploitby Rudi CarellNot analyzed1 file
ExploitDB

PoC details

References

5