CVE Database
/

CVE-2005-3497

Back to search

CVE-2005-3497

Published: Nov 4, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in process_signup.php in PHP Handicapper allows remote attackers to execute arbitrary SQL commands via the serviceid parameter. NOTE: on 20060210, the vendor disputed this issue, saying "this is 100% false reporting, this is a slander campaign from a customer who had a vulnerability in his SERVER not the software." However, followup investigation strongly suggests that the original report is correct

VendorProductVersions

n/a

n/a

affected
n/a

References

20481
vdb-entry
x_refsource_OSVDB
15298
vdb-entry
x_refsource_BID
ADV-2005-2292
vdb-entry
x_refsource_VUPEN
17412
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2005-3497 - Security Vulnerability | QwikSec