7.5
CVSSv2

CVE-2005-3575

Published: 16/11/2005 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in show.php in Cyphor 0.19 and previous versions allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cynox cyphor

Exploits

<?php # quoted from rgod "1)if magic quotes off -> SQL Injection:" /str0ke # # --- cyphor019_xplphp 736 08/10/2005 # # # # Cyphor 019 ( possibly prior versions) SQL injection / board takeover # # ...
#!/bin/env perl #//-----------------------------------------------------------# #// Cyphor Forum SQL Injection Exploit By HACKERS PAL #// Greets For Devil-00 - Abducter - Almaster #// WwWSoQoRNeT #//-----------------------------------------------------------# use LWP::Simple; print "\n ...