SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.
| Software | From | Fixed in |
|---|---|---|
| brooky / estore | 1.0.2b | 1.0.2b.x |