CVE-2005-4035
Web4Future eCommerce Enterprise Edition <2.1 - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
Exploits (3)
References (7)
Core 7
Core References
Third Party Advisory x_refsource_misc
http://pridels0.blogspot.com/2005/12/ecommerce-enterprise-edition-sql-inj.html
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/15707
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/21468
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17881
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2744
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/21467
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/21466
Scores
EPSS
0.0076
EPSS Percentile
73.4%
Details
Status
published
Published
Dec 06, 2005
Tracked Since
Feb 18, 2026