CVE Database
/

CVE-2005-3208

Back to search

CVE-2005-3208

Published: Oct 14, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.

VendorProductVersions

n/a

n/a

affected
n/a

References

17117
third-party-advisory
x_refsource_SECUNIA
19936
vdb-entry
x_refsource_OSVDB
15036
vdb-entry
x_refsource_BID
20051007 Aenovo Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
aenovo-xss(22553)
vdb-entry
x_refsource_XF
aenovo-strsql-sql-injection(22551)
vdb-entry
x_refsource_XF
15038
vdb-entry
x_refsource_BID
19937
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now