Vulnerabilities > CVE-2005-3938 - SQL Injection vulnerability in Softbiz FAQ

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
softbiz
exploit available

Summary

SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.

Vulnerable Configurations

Part Description Count
Application
Softbiz
1

Exploit-Db

  • descriptionSoftBiz FAQ 1.1 faq_qanda.php id Parameter SQL Injection. CVE-2005-3938. Webapps exploit for php platform
    idEDB-ID:26674
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26674/
    titleSoftBiz FAQ 1.1 faq_qanda.php id Parameter SQL Injection
  • descriptionSoftBiz FAQ 1.1 refer_friend.php id Parameter SQL Injection. CVE-2005-3938. Webapps exploit for php platform
    idEDB-ID:26675
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26675/
    titleSoftBiz FAQ 1.1 refer_friend.php id Parameter SQL Injection
  • descriptionSoftBiz FAQ 1.1 add_comment.php id Parameter SQL Injection. CVE-2005-3938. Webapps exploit for php platform
    idEDB-ID:26677
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26677/
    titleSoftBiz FAQ 1.1 add_comment.php id Parameter SQL Injection
  • descriptionSoftBiz FAQ 1.1 index.php cid Parameter SQL Injection. CVE-2005-3938. Webapps exploit for php platform
    idEDB-ID:26673
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26673/
    titleSoftBiz FAQ 1.1 index.php cid Parameter SQL Injection
  • descriptionSoftBiz FAQ 1.1 print_article.php id Parameter SQL Injection. CVE-2005-3938. Webapps exploit for php platform
    idEDB-ID:26676
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26676/
    titleSoftBiz FAQ 1.1 print_article.php id Parameter SQL Injection