CVE-2005-4195
N/A
N/A
Summary
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT–BrowseResources.php, (2) ResourceId parameter in SPT–FullRecord.php, (3) ResourceOffset parameter in SPT–Home.php, and (4) F_UserName and (5) F_Password in SPT–UserLogin.php. NOTE: it was later reported that vector 1 is also present in 1.4.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.osvdb.org/21627
- http://www.securityfocus.com/archive/1/491611/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2844
- http://www.securityfocus.com/bid/15818
- http://www.osvdb.org/21628
- http://www.securityfocus.com/bid/29034
- http://secunia.com/advisories/17979
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42169
- http://www.osvdb.org/21625
- http://www.x-illusion.com/rs/Scout%20Portal%20Toolkit.txt
- https://www.exploit-db.com/exploits/5540
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23547
- http://www.osvdb.org/21626
References
- http://www.osvdb.org/21627
- http://www.securityfocus.com/archive/1/491611/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2844
- http://www.securityfocus.com/bid/15818
- http://www.osvdb.org/21628
- http://www.securityfocus.com/bid/29034
- http://secunia.com/advisories/17979
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42169
- http://www.osvdb.org/21625
- http://www.x-illusion.com/rs/Scout%20Portal%20Toolkit.txt
- https://www.exploit-db.com/exploits/5540
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23547
- http://www.osvdb.org/21626
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.