Vulnerabilities > CVE-2005-4668 - Unspecified vulnerability in Parosproxy
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
References
- http://archives.neohapsis.com/archives/bugtraq/2005-11/0042.html
- http://archives.neohapsis.com/archives/bugtraq/2005-11/0042.html
- http://archives.neohapsis.com/archives/sf/pentest/2005-11/0048.html
- http://archives.neohapsis.com/archives/sf/pentest/2005-11/0048.html
- http://securityreason.com/securityalert/147
- http://securityreason.com/securityalert/147
- http://sourceforge.net/project/shownotes.php?release_id=367666&group_id=84378
- http://sourceforge.net/project/shownotes.php?release_id=367666&group_id=84378
- http://www.osvdb.org/20722
- http://www.osvdb.org/20722