Vulnerabilities > CVE-2005-3555 - Input Validation vulnerability in PHPList

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
tincan
exploit available

Summary

Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.

Exploit-Db

  • descriptionPHPList Mailing List Manager 2.x /admin/editattributes.php id Parameter SQL Injection. CVE-2005-3555. Webapps exploit for php platform
    idEDB-ID:26482
    last seen2016-02-03
    modified2005-11-07
    published2005-11-07
    reporterTobias Klein
    sourcehttps://www.exploit-db.com/download/26482/
    titlePHPList Mailing List Manager 2.x /admin/editattributes.php id Parameter SQL Injection
  • descriptionPHPList Mailing List Manager 2.x /admin/admin.php id Parameter SQL Injection. CVE-2005-3555. Webapps exploit for php platform
    idEDB-ID:26481
    last seen2016-02-03
    modified2005-11-07
    published2005-11-07
    reporterTobias Klein
    sourcehttps://www.exploit-db.com/download/26481/
    titlePHPList Mailing List Manager 2.x /admin/admin.php id Parameter SQL Injection