20050615 Multiple paFileDB Vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=111885787217807&w=2 CVE-2005-2000
PHP Arena 1.1.3 - 'pafiledb.php' Remote Change Password
Record summary
CVE-2005-2000 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP Arena 1.1.3 - 'pafiledb.php' Remote Change PasswordExploitDB exploitby Alpha_ProgrammerNot analyzed1 file
References
5gulftech.org
http://www.gulftech.org/?node=research&article_id=00082-06142005 phparena.netConfirmation
http://www.phparena.net/ phparena.netConfirmation
http://www.phparena.net/pafiledb_patch nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2000