SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=112490781927680&w=2 | |
http://secunia.com/advisories/16566/ | Vendor Advisory |
http://www.security-project.org/projects/board/showthread.php?t=947 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/14654 | Exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/21988 |
Configurations
History
No history.
Information
Published : 2005-08-30 11:45
Updated : 2017-07-11 01:32
NVD link : CVE-2005-2723
Mitre link : CVE-2005-2723
CVE.ORG link : CVE-2005-2723
JSON object : View
Products Affected
php_arena
- pafiledb
CWE