Vulnerability CVE-2005-3838


Published: 2005-11-26   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Isolsoft -> Support center 

 References:
http://www.vupen.com/english/advisories/2005/2592
http://www.securityfocus.com/bid/15570
http://securitytracker.com/id?1015270
http://secunia.com/advisories/17728
http://www.osvdb.org/21102
http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html

Copyright 2024, cxsecurity.com

 

Back to Top