Vulnerability CVE-2005-3953


Published: 2005-12-01   Modified: 2012-02-12

Description:
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Bedeng psp -> Bedeng psp 

 References:
http://www.securityfocus.com/bid/15583
http://www.osvdb.org/21176
http://www.osvdb.org/21175
http://www.osvdb.org/21174
http://secunia.com/advisories/17760
http://pridels0.blogspot.com/2005/11/bedengpsp-sql-inj-vuln.html

Copyright 2024, cxsecurity.com

 

Back to Top