CVE Database
/

CVE-2004-2551

Back to search

CVE-2004-2551

Published: Nov 21, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.

VendorProductVersions

n/a

n/a

affected
n/a

References

8178
vdb-entry
x_refsource_OSVDB
12118
third-party-advisory
x_refsource_SECUNIA
8179
vdb-entry
x_refsource_OSVDB
helpbox-url-gain-access(16774)
vdb-entry
x_refsource_XF
8175
vdb-entry
x_refsource_OSVDB
10776
vdb-entry
x_refsource_BID
8176
vdb-entry
x_refsource_OSVDB
8177
vdb-entry
x_refsource_OSVDB
8172
vdb-entry
x_refsource_OSVDB
8170
vdb-entry
x_refsource_OSVDB
8174
vdb-entry
x_refsource_OSVDB
8171
vdb-entry
x_refsource_OSVDB
8173
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now