Vulnerabilities > CVE-2005-3384 - Scripts Multiple SQL Injection vulnerability in Techno Dreams

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
techno-dreams

Summary

SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Vulnerable Configurations

Part Description Count
Application
Techno_Dreams
1