Vulnerabilities > CVE-2005-0725 - SQL-Injection vulnerability in Wf-Sections 1.07

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
wf-sections
exploit available

Summary

SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.

Vulnerable Configurations

Part Description Count
Application
Wf-Sections
1

Exploit-Db

  • descriptionXOOPS Module Zmagazine 1.0 (print.php) Remote SQL Injection Exploit. CVE-2005-0725,CVE-2007-1974. Webapps exploit for php platform
    fileexploits/php/webapps/3646.pl
    idEDB-ID:3646
    last seen2016-01-31
    modified2007-04-02
    platformphp
    port
    published2007-04-02
    reporterajann
    sourcehttps://www.exploit-db.com/download/3646/
    titleXOOPS Module Zmagazine 1.0 print.php Remote SQL Injection Exploit
    typewebapps
  • descriptionXOOPS Module XFsection <= 1.07 (articleid) BLIND SQL Injection Exploit. CVE-2005-0725,CVE-2007-1974. Webapps exploit for php platform
    fileexploits/php/webapps/3645.html
    idEDB-ID:3645
    last seen2016-01-31
    modified2007-04-02
    platformphp
    port
    published2007-04-02
    reporterajann
    sourcehttps://www.exploit-db.com/download/3645/
    titleXOOPS Module XFsection <= 1.07 articleid BLIND SQL Injection Exploit
    typewebapps
  • descriptionXOOPS Module WF-Section <= 1.01 (articleid) SQL Injection Exploit. CVE-2005-0725,CVE-2007-1974. Webapps exploit for php platform
    fileexploits/php/webapps/3644.pl
    idEDB-ID:3644
    last seen2016-01-31
    modified2007-04-02
    platformphp
    port
    published2007-04-02
    reporterajann
    sourcehttps://www.exploit-db.com/download/3644/
    titleXOOPS Module WF-Section <= 1.01 articleid SQL Injection Exploit
    typewebapps