Vulnerabilities > CVE-2001-0319 - Unspecified vulnerability in IBM products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
Vulnerable Configurations
Exploit-Db
description | IBM Net.Commerce 2.0/3.x/4.x orderdspc.d2w order_rn Option SQL Injection. CVE-2001-0319. Remote exploits for multiple platform |
id | EDB-ID:20618 |
last seen | 2016-02-02 |
modified | 2001-02-05 |
published | 2001-02-05 |
reporter | Rudi Carell |
source | https://www.exploit-db.com/download/20618/ |
title | IBM Net.Commerce 2.0/3.x/4.x orderdspc.d2w order_rn Option SQL Injection |
Nessus
NASL family | CGI abuses |
NASL id | NETCOMMERCE_SQL.NASL |
description | The macro orderdspc.d2w in the remote IBM Net.Commerce 3x is vulnerable to a SQL injection attack via the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11020 |
published | 2002-06-08 |
reporter | This script is Copyright (C) 2002-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11020 |
title | IBM Net.Commerce orderdspc.d2w order_rn Option SQL Injection |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html
- http://www.securityfocus.com/bid/2350
- http://www.securityfocus.com/bid/2350
- http://www-4.ibm.com/software/webservers/commerce/netcomletter.html
- http://www-4.ibm.com/software/webservers/commerce/netcomletter.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6067
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6067