CVE-2005-3884 Information

Description

Multiple SQL injection vulnerabilities in the search action in Zainu 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term and (2) start parameters to index.php.

Reference

http://pridels0.blogspot.com/2005/11/zainu-2x-sql-inj-vuln.html http://secunia.com/advisories/17766 http://www.osvdb.org/21197 http://www.securityfocus.com/bid/15579 http://www.vupen.com/english/advisories/2005/2603 https://exchange.xforce.ibmcloud.com/vulnerabilities/23274

Share on: