SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
References
Configurations
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html - | |
References | () http://secunia.com/advisories/17808 - Vendor Advisory | |
References | () http://www.osvdb.org/21252 - | |
References | () http://www.osvdb.org/21253 - | |
References | () http://www.osvdb.org/21254 - | |
References | () http://www.osvdb.org/21255 - | |
References | () http://www.securityfocus.com/bid/15652 - Exploit |
Information
Published : 2005-12-01 06:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-3937
Mitre link : CVE-2005-3937
CVE.ORG link : CVE-2005-3937
JSON object : View
Products Affected
softbiz
- b2b_trading_marketplace_script
CWE