7.5
CVE-2005-3735
- EPSS 1.51%
- Veröffentlicht 22.11.2005 00:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in e-Quick Cart allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in shopaddtocart.asp, (2) strpemail parameter in shopprojectlogin.asp, and (3) id parameter in shoptellafriend.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.51% | 0.712 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/17652
http://securitytracker.com/id?1015244
http://www.osvdb.org/20997
http://www.osvdb.org/20998
http://www.osvdb.org/20999
http://www.securityfocus.com/bid/15510
http://www.vupen.com/english/advisories/2005/2506