Vulnerabilities > CVE-2005-3914 - SQL Injection vulnerability in Affcommerce 1.1.4

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
affcommerce
exploit available

Summary

Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.

Vulnerable Configurations

Part Description Count
Application
Affcommerce
1

Exploit-Db

  • descriptionAFFCommerce Shopping Cart 1.1.4 ItemReview.php item_id Parameter SQL Injection. CVE-2005-3914. Webapps exploit for php platform
    idEDB-ID:26564
    last seen2016-02-03
    modified2005-11-23
    published2005-11-23
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26564/
    titleAFFCommerce Shopping Cart 1.1.4 ItemReview.php item_id Parameter SQL Injection
  • descriptionAFFCommerce Shopping Cart 1.1.4 SubCategory.php cl Parameter SQL Injection. CVE-2005-3914 . Webapps exploit for php platform
    idEDB-ID:26562
    last seen2016-02-03
    modified2005-11-23
    published2005-11-23
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26562/
    titleAFFCommerce Shopping Cart 1.1.4 SubCategory.php cl Parameter SQL Injection
  • descriptionAFFCommerce Shopping Cart 1.1.4 ItemInfo.php item_id Parameter SQL Injection. CVE-2005-3914. Webapps exploit for php platform
    idEDB-ID:26563
    last seen2016-02-03
    modified2005-11-23
    published2005-11-23
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26563/
    titleAFFCommerce Shopping Cart 1.1.4 ItemInfo.php item_id Parameter SQL Injection