Vulnerabilities > CVE-2005-3978 - SQL Injection vulnerability in Scriptdevelopers.Net Netclassifieds 1.0.1/1.5.1/1.9.6.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
scriptdevelopers-net
exploit available

Summary

Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.

Exploit-Db

  • descriptionNetClassifieds (SQL/XSS/Full Path) Multiple Remote Vulnerabilities. CVE-2005-3978. Webapps exploit for php platform
    idEDB-ID:4092
    last seen2016-01-31
    modified2007-06-22
    published2007-06-22
    reporterlaurent gaffié
    sourcehttps://www.exploit-db.com/download/4092/
    titlenetclassifieds sql/xss/full path Multiple Vulnerabilities
  • descriptionNetClassifieds Standard 1.9/Professional 1.5/Premium 1.0 gallery.php CatID Parameter SQL Injection. CVE-2005-3978. Webapps exploit for php platform
    idEDB-ID:26698
    last seen2016-02-03
    modified2005-12-02
    published2005-12-02
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26698/
    titleNetClassifieds Standard 1.9/Professional 1.5/Premium 1.0 gallery.php CatID Parameter SQL Injection
  • descriptionNetClassifieds Standard 1.9/Professional 1.5/Premium 1.0 ViewItem.php ItemNum Parameter SQL Injection. CVE-2005-3978. Webapps exploit for php platform
    idEDB-ID:26699
    last seen2016-02-03
    modified2005-12-02
    published2005-12-02
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26699/
    titleNetClassifieds Standard 1.9/Professional 1.5/Premium 1.0 ViewItem.php ItemNum Parameter SQL Injection