CVE-2005-3956 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.
Reference
http://pridels0.blogspot.com/2005/11/dmanews-multiple-sql-inj-vuln.html http://secunia.com/advisories/17759 http://www.osvdb.org/21165 http://www.securityfocus.com/bid/15628
Share on: