PT-2005-5169 · Quantum Art · Quantum Art Qp7.Enterprise
CVE-2005-4486
·
Publicado
2005-12-22
·
Atualizado
2024-08-08
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Quantum Art QP7.Enterprise (affected versions not specified)
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
p news id parameter to API endpoints such as "news and events new.asp" and "news.asp". There is a dispute regarding the accuracy of this report from the vendor, but evidence suggests that at least "news and events new.asp" may be vulnerable to forced invalid SQL syntax errors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Quantum Art Qp7.Enterprise