PT-2005-5169 · Quantum Art · Quantum Art Qp7.Enterprise

CVE-2005-4486

·

Publicado

2005-12-22

·

Atualizado

2024-08-08

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Quantum Art QP7.Enterprise (affected versions not specified)
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the p news id parameter to API endpoints such as "news and events new.asp" and "news.asp". There is a dispute regarding the accuracy of this report from the vendor, but evidence suggests that at least "news and events new.asp" may be vulnerable to forced invalid SQL syntax errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4486

Produtos afetados

Quantum Art Qp7.Enterprise