7.5
CVSSv2

CVE-2005-2675

Published: 23/08/2005 Updated: 17/05/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 775
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote malicious users to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter to list.php, (7) m parameter to journal.php, (8) x or (9) n parameter to forums.php, or (10) w parameter to links.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.

Vulnerable Product Search on Vulmon Subscribe to Product

neocrome land down under 800

Exploits

source: wwwsecurityfocuscom/bid/14618/info Land Down Under is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries Successful exploitation may allow the attacker to compromise the application, retrieve sensitive information, modify data, ...
source: wwwsecurityfocuscom/bid/14685/info Land Down Under is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modificatio ...
source: wwwsecurityfocuscom/bid/14618/info Land Down Under is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries Successful exploitation may allow the attacker to compromise the application, retrieve sensitive information, modify dat ...
source: wwwsecurityfocuscom/bid/14618/info Land Down Under is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries Successful exploitation may allow the attacker to compromise the application, retrieve sensitive information, modify data, or ...
source: wwwsecurityfocuscom/bid/14618/info Land Down Under is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries Successful exploitation may allow the attacker to compromise the application, retrieve sensitive information, modify data, o ...