Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.
References
Configurations
History
21 Nov 2024, 00:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2005/12/direct-news-sql-inj.html - | |
References | () http://www.osvdb.org/21854 - Exploit | |
References | () http://www.osvdb.org/22340 - | |
References | () http://www.securityfocus.com/bid/15957/ - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/23727 - |
Information
Published : 2005-12-28 01:03
Updated : 2024-11-21 00:04
NVD link : CVE-2005-4527
Mitre link : CVE-2005-4527
CVE.ORG link : CVE-2005-4527
JSON object : View
Products Affected
direct_news
- direct_news
CWE