| |
Vulnerability CVE-2005-1293
Published: 2005-05-02 Modified: 2012-02-12
Description: |
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. |
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
7.5/10 |
6.4/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
http://secunia.com/advisories/15071
http://digitalparadox.org/advisories/storeportal.txt
http://marc.theaimsgroup.com/?l=bugtraq&m=111445131808328&w=2
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|