PT-2005-4623 · Softbiz · Softbiz Resource Repository Script
Published
2005-11-29
·
Updated
2017-07-20
·
CVE-2005-3879
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Softbiz Resource Repository Script versions 1.1 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
sbres id parameter in files such as "details res.php", "refer friend.php", and "report link.php", and the sbcat id parameter in "showcats.php".Recommendations
For Softbiz Resource Repository Script versions 1.1 and earlier, consider restricting access to the vulnerable parameters
sbres id and sbcat id until a fix is available. As a temporary workaround, avoid using these parameters in the affected files.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Softbiz Resource Repository Script