7.5
CVSSv2

CVE-2005-3877

Published: 29/11/2005 Updated: 07/02/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cafuego simple document management system 1.1.5

cafuego simple document management system

cafuego simple document management system 1.1.4

cafuego simple document management system 1.1.6

Exploits

source: wwwsecurityfocuscom/bid/15596/info Simple Document Management System (SDMS) is prone to SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure o ...
source: wwwsecurityfocuscom/bid/15596/info Simple Document Management System (SDMS) is prone to SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure ...