CVE-2005-3909
Post Affiliate Pro < 2.0.4 - SQL Injection via Sortorder Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3909. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Post Affiliate Pro versions 2.0.4 and prior. It includes example URLs demonstrating how unsanitized input in parameters like 'sortorder' can be exploited to manipulate SQL queries.
Description
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in Post Affiliate Pro versions 2.0.4 and prior. It includes example URLs demonstrating how unsanitized input in parameters like 'sortorder' can be exploited to manipulate SQL queries.