CVE-2005-3646

Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
References
Link Resource
http://marc.info/?l=bugtraq&m=113165036315035&w=2
http://seclists.org/lists/bugtraq/2005/Nov/0189.html
http://secunia.com/advisories/17464/ Patch Vendor Advisory
http://secunia.com/advisories/17579 Vendor Advisory
http://securityreason.com/securityalert/171
http://securityreason.com/securityalert/172
http://securitytracker.com/id?1015193
http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942
http://www.fitsec.com/advisories/FS-05-01.txt Vendor Advisory
http://www.osvdb.org/20744
http://www.osvdb.org/20745
http://www.securityfocus.com/bid/15385/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2380 Vendor Advisory
http://www.zone-h.org/en/advisories/read/id=8413/ Exploit Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/23044
http://marc.info/?l=bugtraq&m=113165036315035&w=2
http://seclists.org/lists/bugtraq/2005/Nov/0189.html
http://secunia.com/advisories/17464/ Patch Vendor Advisory
http://secunia.com/advisories/17579 Vendor Advisory
http://securityreason.com/securityalert/171
http://securityreason.com/securityalert/172
http://securitytracker.com/id?1015193
http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942
http://www.fitsec.com/advisories/FS-05-01.txt Vendor Advisory
http://www.osvdb.org/20744
http://www.osvdb.org/20745
http://www.securityfocus.com/bid/15385/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2380 Vendor Advisory
http://www.zone-h.org/en/advisories/read/id=8413/ Exploit Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/23044
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpadsnew:phpadsnew:2.0.4_pr1:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2.0.7_rc1:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2.0_beta5:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2.0_beta6:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2_dev_2001-09-30:*:*:*:*:*:*:*
cpe:2.3:a:phpadsnew:phpadsnew:2_dev_2001-10-09:*:*:*:*:*:*:*
cpe:2.3:a:phppgads:phppgads:2.0.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:02

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=113165036315035&w=2 - () http://marc.info/?l=bugtraq&m=113165036315035&w=2 -
References () http://seclists.org/lists/bugtraq/2005/Nov/0189.html - () http://seclists.org/lists/bugtraq/2005/Nov/0189.html -
References () http://secunia.com/advisories/17464/ - Patch, Vendor Advisory () http://secunia.com/advisories/17464/ - Patch, Vendor Advisory
References () http://secunia.com/advisories/17579 - Vendor Advisory () http://secunia.com/advisories/17579 - Vendor Advisory
References () http://securityreason.com/securityalert/171 - () http://securityreason.com/securityalert/171 -
References () http://securityreason.com/securityalert/172 - () http://securityreason.com/securityalert/172 -
References () http://securitytracker.com/id?1015193 - () http://securitytracker.com/id?1015193 -
References () http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942 - () http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942 -
References () http://www.fitsec.com/advisories/FS-05-01.txt - Vendor Advisory () http://www.fitsec.com/advisories/FS-05-01.txt - Vendor Advisory
References () http://www.osvdb.org/20744 - () http://www.osvdb.org/20744 -
References () http://www.osvdb.org/20745 - () http://www.osvdb.org/20745 -
References () http://www.securityfocus.com/bid/15385/ - Exploit, Patch () http://www.securityfocus.com/bid/15385/ - Exploit, Patch
References () http://www.vupen.com/english/advisories/2005/2380 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/2380 - Vendor Advisory
References () http://www.zone-h.org/en/advisories/read/id=8413/ - Exploit, Vendor Advisory () http://www.zone-h.org/en/advisories/read/id=8413/ - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23044 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23044 -

Information

Published : 2005-11-17 11:02

Updated : 2024-11-21 00:02


NVD link : CVE-2005-3646

Mitre link : CVE-2005-3646

CVE.ORG link : CVE-2005-3646


JSON object : View

Products Affected

phpadsnew

  • phpadsnew

phppgads

  • phppgads
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')