36437Third-party advisory
http://secunia.com/advisories/36437 CVE-2009-3968
ITechBids 8.0 - 'ProductID' Blind SQL Injection
Record summary
CVE-2009-3968 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php. NOTE: the sellers_othersitem.php, classifieds.php, and shop.php vectors are already covered by CVE-2008-3238.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBITechBids 8.0 - 'ProductID' Blind SQL InjectionExploitDB exploitby Mr.SQLNot analyzed1 file
References
39497exploit
http://www.exploit-db.com/exploits/9497 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3968