Vulnerabilities > CVE-2005-3363 - Input Validation vulnerability in Saphp Saphplesson 1.1/2.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
saphp
exploit available

Summary

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

Vulnerable Configurations

Part Description Count
Application
Saphp
2

Exploit-Db

  • descriptionSaphpLesson 2.0 (forumid) Remote SQL Injection Exploit. CVE-2005-3363. Webapps exploit for php platform
    fileexploits/php/webapps/1530.pl
    idEDB-ID:1530
    last seen2016-01-31
    modified2006-02-25
    platformphp
    port
    published2006-02-25
    reporterSnIpEr_SA
    sourcehttps://www.exploit-db.com/download/1530/
    titleSaphpLesson 2.0 forumid Remote SQL Injection Exploit
    typewebapps
  • descriptionsaphp Lesson add.php forumid Parameter SQL Injection. CVE-2005-3363 . Webapps exploit for php platform
    idEDB-ID:26390
    last seen2016-02-03
    modified2005-10-26
    published2005-10-26
    reporteralmaster
    sourcehttps://www.exploit-db.com/download/26390/
    titlesaphp Lesson add.php forumid Parameter SQL Injection