CVE-2001-0319 | IBM Websphere Commerce Suite up to 4.1.1 Report orderdspc.d2w order_rn sql injection (EDB-20618 / Nessus ID 11020)
A vulnerability classified as critical has been found in IBM Websphere Commerce Suite up to 4.1.1. This affects an unknown function of the file orderdspc.d2w of the component Report Handler. The manipulation of the argument order_rn leads to sql injection.
This vulnerability is listed as CVE-2001-0319. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to upgrade the affected component.