CVE-2005-3953
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-3953. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Bedeng PSP, where the 'cwhere' parameter in the URL is not properly sanitized, allowing attackers to inject malicious SQL queries. The example URL demonstrates the vulnerable parameter but does not include executable exploit code.
Description
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
Exploits (3)
The provided text describes a SQL injection vulnerability in Bedeng PSP, where the 'cwhere' parameter in the URL is not properly sanitized, allowing attackers to inject malicious SQL queries. The example URL demonstrates the vulnerable parameter but does not include executable exploit code.
The provided text describes a SQL injection vulnerability in Bedeng PSP, where the 'cwhere' parameter in /download.php is not properly sanitized. The example shows how an attacker can inject SQL code via the 'a.ngroup' parameter.
The provided text describes a SQL injection vulnerability in Bedeng PSP, where the 'ckode' parameter in '/baca.php' is not properly sanitized. This allows attackers to inject malicious SQL queries, potentially leading to data disclosure or modification.