CVE-2005-3578

Walla TeleSite < 3.0 - SQL Injection via ts.exe sug Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3578. PoCs published by Rafi Nahum.

AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Walla TeleSite 3.0 due to improper input sanitization. It includes crafted URLs that manipulate the 'sug' parameter to execute SQL queries and potentially disclose sensitive information.

Description

SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rafi Nahum · textwebappscgi
https://www.exploit-db.com/exploits/26508

The exploit demonstrates SQL injection and XSS vulnerabilities in Walla TeleSite 3.0 due to improper input sanitization. It includes crafted URLs that manipulate the 'sug' parameter to execute SQL queries and potentially disclose sensitive information.

Classification
Working Poc 90%
Attack Type
Sqli | Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Walla TeleSite 3.0 and earlier
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/416581/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015204
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20883
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15419

Scores

EPSS 0.0116
EPSS Percentile 63.3%

Details

Status published
Products (1)
walla_telesite/walla_telesite < 3.0
Published Nov 16, 2005
Tracked Since Feb 18, 2026