Vulnerabilities > CVE-2005-4563 - SQL Injection vulnerability in Enterprise Heart Enterprise Connector 1.0.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
enterprise-heart
exploit available

Summary

SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.

Vulnerable Configurations

Part Description Count
Application
Enterprise_Heart
1

Exploit-Db

descriptionEnterprise Connector 1.0.2 Main.PHP SQL Injection Vulnerability. CVE-2005-4563. Webapps exploit for php platform
idEDB-ID:26916
last seen2016-02-03
modified2005-12-20
published2005-12-20
reporterAttila Gerendi
sourcehttps://www.exploit-db.com/download/26916/
titleEnterprise Connector 1.0.2 Main.PHP SQL Injection Vulnerability