7.5

CVE-2005-3868

Exploit
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Turn-kK-search Version <= 1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html
http://secunia.com/advisories/17719
Vendor Advisory
http://www.exploit-db.com/exploits/13993
http://www.osvdb.org/21127
http://www.securityfocus.com/bid/15588
Exploit
http://www.vupen.com/english/advisories/2005/2616