PT-2005-5169 · Quantum Art · Quantum Art Qp7.Enterprise
Published
2005-12-22
·
Updated
2024-08-08
·
CVE-2005-4486
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Quantum Art QP7.Enterprise (affected versions not specified)
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
p news id parameter to API endpoints such as "news and events new.asp" and "news.asp". There is a dispute regarding the accuracy of this report from the vendor, but evidence suggests that at least "news and events new.asp" may be vulnerable to forced invalid SQL syntax errors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quantum Art Qp7.Enterprise