CVE-2005-3956
DMANews 0.904 and 0.910 - SQL Injection via id, sortorder, or display_num Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3956. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in DMANews versions 0.904 and 0.910, detailing vulnerable parameters in the application's URL structure. It does not include executable exploit code but outlines the attack vectors.
Description
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.
Exploits (1)
The provided text describes SQL injection vulnerabilities in DMANews versions 0.904 and 0.910, detailing vulnerable parameters in the application's URL structure. It does not include executable exploit code but outlines the attack vectors.