Vulnerabilities > CVE-2005-4064 - SQL Injection vulnerability in Alan Ward A-Faq 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
alan-ward
exploit available

Summary

Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.

Vulnerable Configurations

Part Description Count
Application
Alan_Ward
1

Exploit-Db

  • descriptionA-FAQ 1.0 faqDspItem.asp faqid Parameter SQL Injection. CVE-2005-4064. Webapps exploit for asp platform
    idEDB-ID:26746
    last seen2016-02-03
    modified2005-12-06
    published2005-12-06
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26746/
    titleA-FAQ 1.0 faqDspItem.asp faqid Parameter SQL Injection
  • descriptionA-FAQ 1.0 faqDsp.asp catcode Parameter SQL Injection. CVE-2005-4064. Webapps exploit for asp platform
    idEDB-ID:26747
    last seen2016-02-03
    modified2005-12-06
    published2005-12-06
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26747/
    titleA-FAQ 1.0 faqDsp.asp catcode Parameter SQL Injection