CVE-2005-3646
CVE-2005-3646
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://marc.info/?l=bugtraq&m=113165036315035&w=2http://seclists.org/lists/bugtraq/2005/Nov/0189.htmlhttp://secunia.com/advisories/17464/http://secunia.com/advisories/17579http://securityreason.com/securityalert/171http://securityreason.com/securityalert/172http://securitytracker.com/id?1015193https://exchange.xforce.ibmcloud.com/vulnerabilities/23044http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=370942http://www.fitsec.com/advisories/FS-05-01.txthttp://www.osvdb.org/20744http://www.osvdb.org/20745