CVE-2014-3871 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.
Reference
http://geodesicsolutions.com/changelog/7.3/changelog.html http://osvdb.org/show/osvdb/106364 http://packetstormsecurity.com/files/126329/GeoCore-MAX-DB-7.3.3-Blind-SQL-Injection.html http://secunia.com/advisories/58308 http://www.exploit-db.com/exploits/33075 http://www.securityfocus.com/bid/67078
Share on: