7.5
CVSSv2

CVE-2005-4168

Published: 11/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote malicious users to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.

Vulnerable Product Search on Vulmon Subscribe to Product

efiction project efiction 1.0

efiction project efiction 1.1

efiction project efiction 2.0

Exploits

source: wwwsecurityfocuscom/bid/15568/info eFiction is prone to SQL injection, remote file upload, and cross site scripting vulnerabilities These vulnerabilities may allow an attacker to view and modify sensitive information, gain unauthorized access, modify and corrupt the underlying database application, and obtain a victim's authen ...