CVE-2006-6207

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/12/2006
Last modified:
09/04/2025

Description

SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lynx_internet_solutions:evolve_merchant:*:*:*:*:*:*:*:*