Vulnerability CVE-2005-4554


Published: 2005-12-28   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
DEV -> Dev web management system 

 References:
http://rgod.altervista.org/dev_15_sql_xpl.html
http://securitytracker.com/id?1015410
http://www.securityfocus.com/archive/1/420253/100/0/threaded
http://www.securityfocus.com/bid/16063
https://exchange.xforce.ibmcloud.com/vulnerabilities/23898

Copyright 2024, cxsecurity.com

 

Back to Top