7.5
CVE-2005-1161
- EPSS 3.59%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:12:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.59% | 0.879 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=111352017704126&w=2
http://secunia.com/advisories/14969
http://securitytracker.com/id?1013720
http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab
http://www.osvdb.org/15518
http://www.osvdb.org/15519
http://www.osvdb.org/15520
http://www.securityfocus.com/bid/13181
http://www.securityfocus.com/bid/13182
http://www.securityfocus.com/bid/13183
https://exchange.xforce.ibmcloud.com/vulnerabilities/20097