CVE-2005-1673 Information

Description

Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php (2) tid parameter to view.php fid parameter to (3) download.php or (4) chat_download.php (5) status parameter to icon.php TICKET_tid parameter to (6) index.php or (7) view.php.

Reference

http://www.gulftech.org/?node=research&article_id=00076-05172005 http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0

Share on: