PT-2005-3150 · Dragonfly · Dragonfly Commerce
Diabolic Crab
·
Published
2005-07-12
·
Updated
2024-08-07
·
CVE-2005-2221
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Dragonfly Commerce versions (affected versions not specified)
Description:
The issue allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via several parameters, including the
key parameter to "dc Categoriesview.asp", the PID parameter to "ratings.asp", the start, key mp, searchtype, or psearch parameters to "dc forum Postslist.asp". The vendor has disputed this issue, stating that the error messages arise from invalid category and product numbers. However, the issue still satisfies the definition of exposure.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dragonfly Commerce