Описание
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2005-3646
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23044
- http://marc.info/?l=bugtraq&m=113165036315035&w=2
- http://seclists.org/lists/bugtraq/2005/Nov/0189.html
- http://secunia.com/advisories/17464
- http://secunia.com/advisories/17579
- http://securityreason.com/securityalert/171
- http://securityreason.com/securityalert/172
- http://securitytracker.com/id?1015193
- http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942
- http://www.fitsec.com/advisories/FS-05-01.txt
- http://www.osvdb.org/20744
- http://www.osvdb.org/20745
- http://www.securityfocus.com/bid/15385
- http://www.vupen.com/english/advisories/2005/2380
- http://www.zone-h.org/en/advisories/read/id=8413
Связанные уязвимости
nvd
около 20 лет назад
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.