7.5

CVE-2005-3937

Exploit
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.678
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html
Broken Link
http://secunia.com/advisories/17808
Third Party Advisory
http://www.osvdb.org/21252
Broken Link
http://www.osvdb.org/21253
Broken Link
http://www.osvdb.org/21254
Broken Link
http://www.osvdb.org/21255
Broken Link
http://www.securityfocus.com/bid/15652
Broken Link