7.5

CVE-2005-3817

Exploit
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php,  (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.09% 0.894
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://pridels0.blogspot.com/2005/11/web-host-directory-script-multiple.html
Broken Link
http://secunia.com/advisories/17724
Third Party Advisory
http://www.osvdb.org/21079
Broken Link
http://www.osvdb.org/21080
Broken Link
http://www.osvdb.org/21081
Broken Link
http://www.osvdb.org/21082
Broken Link
http://www.osvdb.org/21083
Broken Link
http://www.securityfocus.com/bid/15561
Broken Link
http://www.vupen.com/english/advisories/2005/2557
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/23208
Third Party Advisory