Vulnerabilities > CVE-2005-2404 - SQL Injection vulnerability in Sendcard 3.2.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sendcard
nessus

Summary

SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Vulnerable Configurations

Part Description Count
Application
Sendcard
1

Nessus

NASL familyCGI abuses
NASL idSENDCARD_SQL.NASL
descriptionThe remote host is running Sendcard, a multi-database e-card program written in PHP. The version of Sendcard installed on the remote host is prone to a SQL injection attack due to its failure to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id19748
published2005-09-19
reporter(C) 2005-2018 Josh Zlatin-Amishav
sourcehttps://www.tenable.com/plugins/nessus/19748
titleSendcard sendcard.php id Parameter SQL Injection