CVE-2010-4362

Micronetsoft RV Dealer Website - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.

Exploits (1)

exploitdb WRITEUP VERIFIED
by underground-stockholm.com · textwebappsasp
https://www.exploit-db.com/exploits/15629

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15629
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45089
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41319

Scores

EPSS 0.0027
EPSS Percentile 49.9%

Details

CWE
CWE-89
Status published
Products (1)
micronetsoft/rv_dealer_website
Published Dec 01, 2010
Tracked Since Feb 18, 2026