Vulnerabilities > CVE-2005-4419 - Input Validation vulnerability in Quick Square Development Honeycomb Archive
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Quick Square Development Honeycomb Archive 3.0 CategoryResults.cfm Multiple Parameter SQL Injection. CVE-2005-4419 . Webapps exploit for cfm platform |
id | EDB-ID:26920 |
last seen | 2016-02-03 |
modified | 2005-12-20 |
published | 2005-12-20 |
reporter | r0t3d3Vil |
source | https://www.exploit-db.com/download/26920/ |
title | Quick Square Development Honeycomb Archive 3.0 CategoryResults.cfm Multiple Parameter SQL Injection |
References
- http://pridels0.blogspot.com/2005/12/honeycomb-archive-honeycomb-archive.html
- http://secunia.com/advisories/18127
- http://www.attrition.org/pipermail/vim/2006-March/000580.html
- http://www.osvdb.org/21827
- http://www.securityfocus.com/bid/15995
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23829