CVE-2005-2398

Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:php_surveyor:php_surveyor:0.98:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-07-27 04:00

Updated : 2024-02-04 16:52


NVD link : CVE-2005-2398

Mitre link : CVE-2005-2398

CVE.ORG link : CVE-2005-2398


JSON object : View

Products Affected

php_surveyor

  • php_surveyor