cpe:/a:jce-tech:shareasale_script:1.0 CVE-2010-2460 2010-06-25T17:30:01.390-04:00 2017-08-16T21:32:44.197-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2010-06-28T12:36:00.000-04:00 EXPLOIT-DB 13949 BID 40993 XF shareasalescript-merchpdlist-sql-injection(59581) SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.