7.5
CVSSv2

CVE-2005-3952

Published: 01/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in PHP Labs Top Auction allows remote malicious users to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.

Vulnerable Product Search on Vulmon Subscribe to Product

php labs top auction 1.0

Exploits

#!/usr/bin/perl #[Script Name: Top Auction 10 (viewcatphp) Remote Blind SQL Injection Exploit #[Coded by : ajann #[Author : ajann #[Contact : :( #[SPage : wwwphplabscom #[$$ : 3995$ #[ : ajann,Turkey use IO::Socket; if(@ARGV < 1){ print " [============================================================== ...