Vulnerabilities > CVE-2005-4822 - SQL Injection vulnerability in Digger Solutions Intranet Open Source Project-Edit.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
digger-solutions

Summary

SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter.

Vulnerable Configurations

Part Description Count
Application
Digger_Solutions
1