7.5
CVE-2005-3937
- EPSS 1.35%
- Veröffentlicht 01.12.2005 06:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softbizscripts ≫ B2b Trading Marketplace Script Version <= 1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.678 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html
http://secunia.com/advisories/17808
http://www.osvdb.org/21252
http://www.osvdb.org/21253
http://www.osvdb.org/21254
http://www.osvdb.org/21255
http://www.securityfocus.com/bid/15652