Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-3868

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-3868
Last Modified 07 Mar 2011 09:27:18
Published 29 Nov 2005 06:03:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-3868

Summary

Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.

Vulnerable Systems

Application

  • Turn-k K-search 1.0


References

VUPEN - ADV-2005-2616

BID - 15588

EXPLOIT-DB - 13993

SECUNIA - 17719

OSVDB - 21127

MISC - http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html


Last Updated: 27 May 2016 10:41:04