CVE-2005-3840 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo an Internet Explorer issue was incorrectly assigned this identifier but the correct identifier is CVE-2005-3240.
Reference
http://pridels0.blogspot.com/2005/11/omnistar-live-id-and-categoryid-sql.html http://secunia.com/advisories/17697 http://www.osvdb.org/21077 http://www.vupen.com/english/advisories/2005/2561
Share on: