7.5
CVSSv2

CVE-2005-3939

Published: 01/12/2005 Updated: 03/10/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote malicious users to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wsn knowledge base wsn knowledge base

Exploits

source: wwwsecurityfocuscom/bid/15656/info WSN Knowledge Base is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure or modificatio ...
source: wwwsecurityfocuscom/bid/15656/info WSN Knowledge Base is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure or modificat ...
source: wwwsecurityfocuscom/bid/15656/info WSN Knowledge Base is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure or modific ...