Vulnerabilities > CVE-2005-4137 - Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
fad-solutions

Summary

SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.

Vulnerable Configurations

Part Description Count
Application
Fad_Solutions
1