PT-2005-5197 · Webdb · Webdb
Published
2005-12-23
·
Updated
2024-08-08
·
CVE-2005-4515
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WebDB versions 1.1 and earlier
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly
Search0. The vendor has disputed this issue, stating that the flaw was in custom code added for a client and has since been removed, with no installations or patches required for clients.Recommendations
For WebDB versions 1.1 and earlier, no action is required on the part of customers, as the vendor has removed the flawed code and all users of the software begin to use the latest changes immediately.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webdb