CVE-2005-3827
agilebill < 1.4.92 - SQL Injection via product_cat id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3827. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in AgileBill version 1.4.92, where user-supplied input is not properly sanitized before being used in an SQL query. The example URL demonstrates how an attacker could inject malicious SQL code via the 'id' parameter.
Description
SQL injection vulnerability in product_cat in AgileBill 1.4.92 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in AgileBill version 1.4.92, where user-supplied input is not properly sanitized before being used in an SQL query. The example URL demonstrates how an attacker could inject malicious SQL code via the 'id' parameter.