Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php.
References
Link | Resource |
---|---|
http://secunia.com/advisories/10786/ | Patch Vendor Advisory |
http://www.securityfocus.com/archive/1/352598 | Exploit Patch |
http://www.securityfocus.com/bid/9574 | Exploit |
http://www.zone-h.org/en/advisories/read/id=3864/ | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15035 | |
http://secunia.com/advisories/10786/ | Patch Vendor Advisory |
http://www.securityfocus.com/archive/1/352598 | Exploit Patch |
http://www.securityfocus.com/bid/9574 | Exploit |
http://www.zone-h.org/en/advisories/read/id=3864/ | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15035 |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/10786/ - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/352598 - Exploit, Patch | |
References | () http://www.securityfocus.com/bid/9574 - Exploit | |
References | () http://www.zone-h.org/en/advisories/read/id=3864/ - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15035 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:52
NVD link : CVE-2004-2175
Mitre link : CVE-2004-2175
CVE.ORG link : CVE-2004-2175
JSON object : View
Products Affected
all_enthusiast_inc
- reviewpost_php_pro
CWE