CVE-2005-2561

Multiple SQL injection vulnerabilities in MYFAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the Theme parameter to (1) affichagefaq.php3, (2) choixsoustheme.php3, (3) consultation.php3, (4) insfaq.php3, (5) inssoustheme.php3, (6) instheme.php3, (7) saisiefaqtotale.php3, (8) saisiesoustheme.php3, or (9) voirfaq.php3, the SousTheme parameter to (10) affichagefaq.php3, (11) consultation.php3, (12) insfaq.php3, (13) inssoustheme.php3, (14) saisiefaq.php3, (15) saisiefaqtotale.php3, or (16) voirfaq.php3, the Faq parameter to (17) saisiefaq.php3, (18) voirfaq.php3, or (19) inssolution.php3, or (20) question parameter to affichagefaq.php3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:myfaq:myfaq:1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112352204602309&w=2 - () http://marc.info/?l=bugtraq&m=112352204602309&w=2 -
References () http://secunia.com/advisories/16366 - () http://secunia.com/advisories/16366 -
References () http://svt.nukleon.us/lab/svadvisory13.txt - () http://svt.nukleon.us/lab/svadvisory13.txt -
References () http://www.securityfocus.com/bid/14503 - () http://www.securityfocus.com/bid/14503 -

Information

Published : 2005-08-16 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2005-2561

Mitre link : CVE-2005-2561

CVE.ORG link : CVE-2005-2561


JSON object : View

Products Affected

myfaq

  • myfaq