20050209 CMS Core SQL injectionmailing list
http://marc.info/?l=bugtraq&m=110803385223054&w=2 CVE-2005-0368
CMScore - SQL Injection
Record summary
CVE-2005-0368 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMScore - SQL InjectionExploitDB exploitby GHCNot analyzed1 file
References
514142Third-party advisory
http://secunia.com/advisories/14142 12457vdb entry
http://www.securityfocus.com/bid/12457 cmscore-multiple-sql-injection(19235)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19235 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0368