5
CVSSv2

CVE-2005-0410

Published: 14/02/2005 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and previous versions allows remote malicious users to inject data via the fields of a CSV file.

Vulnerable Product Search on Vulmon Subscribe to Product

citrusdb citrusdb

Exploits

source: wwwsecurityfocuscom/bid/12557/info CitrusDB is reportedly affected by an access validation vulnerability during the upload of CSV files Exploitation of this issue could result in path disclosure or SQL injection The issue exists because the application fails to verify user credentials during file upload and import These is ...