PT-2005-4584 · Desklance · Desklance

Published

2005-11-26

·

Updated

2011-03-08

·

CVE-2005-3836

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DeskLance versions 2.3 and earlier
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the announce parameter.
Recommendations For DeskLance versions 2.3 and earlier, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting access to the announce parameter to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3836

Affected Products

Desklance