CVE Database
/

CVE-2005-2473

Back to search

CVE-2005-2473

Published: Aug 5, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

18416
vdb-entry
x_refsource_OSVDB
18411
vdb-entry
x_refsource_OSVDB
18423
vdb-entry
x_refsource_OSVDB
20050801 ChurchInfo Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
18421
vdb-entry
x_refsource_OSVDB
18418
vdb-entry
x_refsource_OSVDB
18413
vdb-entry
x_refsource_OSVDB
14438
vdb-entry
x_refsource_BID
18417
vdb-entry
x_refsource_OSVDB
1014617
vdb-entry
x_refsource_SECTRACK
18420
vdb-entry
x_refsource_OSVDB
18415
vdb-entry
x_refsource_OSVDB
18428
vdb-entry
x_refsource_OSVDB
18414
vdb-entry
x_refsource_OSVDB
18427
vdb-entry
x_refsource_OSVDB
18422
vdb-entry
x_refsource_OSVDB
18410
vdb-entry
x_refsource_OSVDB
18412
vdb-entry
x_refsource_OSVDB
18408
vdb-entry
x_refsource_OSVDB
18424
vdb-entry
x_refsource_OSVDB
18409
vdb-entry
x_refsource_OSVDB
churchinfo-sql-injection(21647)
vdb-entry
x_refsource_XF
18419
vdb-entry
x_refsource_OSVDB
16292
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now