Vulnerabilities > Affcommerce > Affcommerce > 1.1.4

DATE CVE VULNERABILITY TITLE RISK
2005-11-30 CVE-2005-3914 SQL Injection vulnerability in Affcommerce 1.1.4
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
network
low complexity
affcommerce
6.4