CVE-2005-3978
NetClassifieds - SQL Injection via CatID or ItemNum Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-3978. PoCs published by laurent gaffié, r0t.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in NetClassifieds due to improper input sanitization in the `CCGetFromGet` and `CCGetFromPost` functions. Proof-of-concept examples show how to extract sensitive data like passwords via SQLi.
Description
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.
Exploits (3)
The exploit demonstrates SQL injection and XSS vulnerabilities in NetClassifieds due to improper input sanitization in the `CCGetFromGet` and `CCGetFromPost` functions. Proof-of-concept examples show how to extract sensitive data like passwords via SQLi.
This is a vulnerability writeup describing SQL injection flaws in NetClassifieds due to improper input sanitization. It provides a basic example URL but lacks executable exploit code.
The provided text describes a SQL injection vulnerability in NetClassifieds, where the 'CatID' parameter in 'gallery.php' is not properly sanitized. It lacks actual exploit code but references a known CVE and vulnerability details.