Re: Evolve Merchant[ injection sql ]

2006-12-05 Thread tony
We have fixed the (original) viewcart.asp?zoneid one, that was a legitimate sql injection hole. The (other) products.asp?pa rtno is not a sql-injection vulnerability. However it does put up a sql error message if an unknown partno is passed. So the researcher would have put in an

Evolve Merchant[ injection sql ]

2006-11-14 Thread saps . audit
vendor site:http://www.lynxinternet.com/ product:Evolve Merchant bug:injection sql risk:medium injection sql (get) : http://site.com/viewcart.asp?zoneid='[sql] laurent gaffié benjamin mossé http://s-a-p.ca/ contact: [EMAIL PROTECTED]