CVE-2005-3578
Walla TeleSite < 3.0 - SQL Injection via ts.exe sug Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3578. PoCs published by Rafi Nahum.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Walla TeleSite 3.0 due to improper input sanitization. It includes crafted URLs that manipulate the 'sug' parameter to execute SQL queries and potentially disclose sensitive information.
Description
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in Walla TeleSite 3.0 due to improper input sanitization. It includes crafted URLs that manipulate the 'sug' parameter to execute SQL queries and potentially disclose sensitive information.