CVE Database
/

CVE-2005-4227

Back to search

CVE-2005-4227

Published: Dec 14, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_member_id, year, agid, day, day_s, hour, minute, month, month_s, and year_s parameters in calendar.php, (4) the cid parameter in contents.php, (5) the dcp5_member_id parameter in forums.php, (6) the bid parameter in go.php, (7) the lid parameter in golink.php, (8) the dcp5_member_id and mid parameters in inbox.php, (9) the catid, dcat, and dl parameters in index.php, (10) the dcp5_member_id in informer.php, (11) the nid parameter in news.php, (12) the type and rate parameters in rate.php, (13) the q parameter in search.php, and (14) the dcp5_member_id in update.php. NOTE: other vectors in the PHP-CHECKER report are also covered by CVE-2005-3365 and CVE-2005-0454.

VendorProductVersions

n/a

n/a

affected
n/a

References

22021
vdb-entry
x_refsource_OSVDB
22028
vdb-entry
x_refsource_OSVDB
22027
vdb-entry
x_refsource_OSVDB
22017
vdb-entry
x_refsource_OSVDB
22025
vdb-entry
x_refsource_OSVDB
22026
vdb-entry
x_refsource_OSVDB
12751
third-party-advisory
x_refsource_SECUNIA
22020
vdb-entry
x_refsource_OSVDB
22031
vdb-entry
x_refsource_OSVDB
22030
vdb-entry
x_refsource_OSVDB
22023
vdb-entry
x_refsource_OSVDB
22024
vdb-entry
x_refsource_OSVDB
15183
vdb-entry
x_refsource_BID
ADV-2005-2863
vdb-entry
x_refsource_VUPEN
22019
vdb-entry
x_refsource_OSVDB
22022
vdb-entry
x_refsource_OSVDB
22029
vdb-entry
x_refsource_OSVDB
22018
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now