CVE-2005-4035

Web4Future eCommerce Enterprise Edition <2.1 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26719
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26718
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26717

Scores

EPSS 0.0076
EPSS Percentile 73.1%

Classification

Status draft

Timeline

Published Dec 06, 2005
Tracked Since Feb 18, 2026