Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-3978
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3978

Description:
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA17853

OSVDB
  21378
  21379
  21380

MISC
  http://pridels.blogspot.com/2005/12/netclassifieds-all-versions-sql-inj.html

BID
  15683


Return to the previous page.