PT-2005-5169 · Quantum Art · Quantum Art Qp7.Enterprise

Published

2005-12-22

·

Updated

2024-08-08

·

CVE-2005-4486

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Quantum Art QP7.Enterprise (affected versions not specified)
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the p news id parameter to API endpoints such as "news and events new.asp" and "news.asp". There is a dispute regarding the accuracy of this report from the vendor, but evidence suggests that at least "news and events new.asp" may be vulnerable to forced invalid SQL syntax errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2005-4486

Affected Products

Quantum Art Qp7.Enterprise