Vulnerabilities > CVE-2005-4408 - SQL Injection vulnerability in Miraserver

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pc-media
exploit available

Summary

Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.

Vulnerable Configurations

Part Description Count
Application
Pc_Media
1

Exploit-Db

  • descriptionMiraserver 1.0 RC4 article.php cat Parameter SQL Injection. CVE-2005-4408. Webapps exploit for php platform
    idEDB-ID:26902
    last seen2016-02-03
    modified2005-12-19
    published2005-12-19
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26902/
    titleMiraserver 1.0 RC4 article.php cat Parameter SQL Injection
  • descriptionMiraserver 1.0 RC4 newsitem.php id Parameter SQL Injection. CVE-2005-4408. Webapps exploit for php platform
    idEDB-ID:26901
    last seen2016-02-03
    modified2005-12-19
    published2005-12-19
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26901/
    titleMiraserver 1.0 RC4 newsitem.php id Parameter SQL Injection
  • descriptionMiraserver 1.0 RC4 index.php page Parameter SQL Injection. CVE-2005-4408 . Webapps exploit for php platform
    idEDB-ID:26900
    last seen2016-02-03
    modified2005-12-19
    published2005-12-19
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26900/
    titleMiraserver 1.0 RC4 index.php page Parameter SQL Injection