Vulnerabilities > CVE-2005-2896 - SQL Injection vulnerability in Stylemotion web News 1.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
stylemotion
exploit available

Summary

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

Vulnerable Configurations

Part Description Count
Application
Stylemotion
1

Exploit-Db

  • descriptionStylemotion WEB//NEWS 1.4 startup.php Cookie SQL Injection. CVE-2005-2896. Webapps exploit for php platform
    idEDB-ID:26234
    last seen2016-02-03
    modified2005-09-08
    published2005-09-08
    reporteronkel_fisch
    sourcehttps://www.exploit-db.com/download/26234/
    titleStylemotion WEB//NEWS 1.4 - startup.php Cookie SQL Injection
  • descriptionStylemotion WEB//NEWS 1.4 print.php id Parameter SQL Injection. CVE-2005-2896. Webapps exploit for php platform
    idEDB-ID:26236
    last seen2016-02-03
    modified2005-09-08
    published2005-09-08
    reporteronkel_fisch
    sourcehttps://www.exploit-db.com/download/26236/
    titleStylemotion WEB//NEWS 1.4 - print.php id Parameter SQL Injection