digitalparadox.org
http://digitalparadox.org/viewadvisories.ah?view=37 CVE-2005-1413
EnViVo!CMS - 'default.asp?ID' SQL Injection
Record summary
CVE-2005-1413 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEnViVo!CMS - 'default.asp?ID' SQL InjectionExploitDB exploitby duritoNot analyzed1 file
References
Showing 12 of 1420070711 durito: enVivo!CMS SQL injectionmailing list
http://marc.info/?l=full-disclosure&m=118414271202945&w=2 15173Third-party advisory
http://secunia.com/advisories/15173 1013843vdb entry
http://securitytracker.com/id?1013843 securityvulns.ru
http://securityvulns.ru/Rdocument425.html 15964vdb entry
http://www.osvdb.org/15964 15965vdb entry
http://www.osvdb.org/15965 15966vdb entry
http://www.osvdb.org/15966 13437vdb entry
http://www.securityfocus.com/bid/13437 13439vdb entry
http://www.securityfocus.com/bid/13439 13440vdb entry
http://www.securityfocus.com/bid/13440 24860vdb entry
http://www.securityfocus.com/bid/24860