CVE-2005-4527
N/A
N/A
Summary
Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/15957/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23727
- http://www.osvdb.org/21854
- http://pridels0.blogspot.com/2005/12/direct-news-sql-inj.html
- http://www.osvdb.org/22340
References
- http://www.securityfocus.com/bid/15957/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23727
- http://www.osvdb.org/21854
- http://pridels0.blogspot.com/2005/12/direct-news-sql-inj.html
- http://www.osvdb.org/22340
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.