Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.
References
Configurations
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=112206702015439&w=2 - | |
References | () http://secunia.com/advisories/16169 - | |
References | () http://securitytracker.com/id?1014554 - | |
References | () http://www.hardened-php.net/advisory_112005.59.html - Exploit, Patch, Vendor Advisory | |
References | () http://www.osvdb.org/18166 - | |
References | () http://www.osvdb.org/18167 - | |
References | () http://www.securityfocus.com/bid/14352 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/21482 - |
Information
Published : 2005-08-03 04:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2415
Mitre link : CVE-2005-2415
CVE.ORG link : CVE-2005-2415
JSON object : View
Products Affected
astalavista_it_engineering
- contrexx
CWE