CVE-2005-3939

Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wsn_knowledge_base:wsn_knowledge_base:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://pridels0.blogspot.com/2005/11/wsn-knowledge-base-sql-inj-vuln.html - () http://pridels0.blogspot.com/2005/11/wsn-knowledge-base-sql-inj-vuln.html -
References () http://secunia.com/advisories/17810 - Vendor Advisory () http://secunia.com/advisories/17810 - Vendor Advisory
References () http://www.osvdb.org/21262 - () http://www.osvdb.org/21262 -
References () http://www.osvdb.org/21263 - () http://www.osvdb.org/21263 -
References () http://www.osvdb.org/21264 - () http://www.osvdb.org/21264 -
References () http://www.securityfocus.com/bid/15656 - Exploit () http://www.securityfocus.com/bid/15656 - Exploit

Information

Published : 2005-12-01 06:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-3939

Mitre link : CVE-2005-3939

CVE.ORG link : CVE-2005-3939


JSON object : View

Products Affected

wsn_knowledge_base

  • wsn_knowledge_base