PT-2005-1718 · Zorum · Zorum

Published

2005-03-07

·

Updated

2008-09-05

·

CVE-2005-0676

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zorum version 3.5
Description The issue allows remote attackers to trigger an SQL error and possibly inject arbitrary SQL commands via the search capability in index.php.
Recommendations For Zorum version 3.5, consider disabling the search capability until a patch is available to prevent potential SQL injection attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0676

Affected Products

Zorum