CVE-2005-3978 Information

Description

Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1 Professional Edition 1.5.1 Standard Edition 1.9.6.3 and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php and the (2) ItemNum parameter in (c) ViewItem.php.

Reference

http://pridels0.blogspot.com/2005/12/netclassifieds-all-versions-sql-inj.html http://secunia.com/advisories/17853 http://www.osvdb.org/21378 http://www.osvdb.org/21379 http://www.osvdb.org/21380 http://www.securityfocus.com/bid/15683 http://www.vupen.com/english/advisories/2005/2689

Share on: