CVE Database
/

CVE-2005-4366

Back to search

CVE-2005-4366

Published: Dec 20, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php; (2) the customerPlanID parameter to viewplan.php; (3) the ref_id parameter to referred_plans.php; (4) customerPlanID parameter to listcharges.php; and (5) the domain parameter to (k) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php. NOTE: the viewinvoice.php invoiceID vector is already covered by CVE-2005-4137.

VendorProductVersions

n/a

n/a

affected
n/a

References

21186
vdb-entry
x_refsource_OSVDB
21183
vdb-entry
x_refsource_OSVDB
21189
vdb-entry
x_refsource_OSVDB
21187
vdb-entry
x_refsource_OSVDB
21181
vdb-entry
x_refsource_OSVDB
21180
vdb-entry
x_refsource_OSVDB
21184
vdb-entry
x_refsource_OSVDB
21188
vdb-entry
x_refsource_OSVDB
21182
vdb-entry
x_refsource_OSVDB
21179
vdb-entry
x_refsource_OSVDB
21192
vdb-entry
x_refsource_OSVDB
21190
vdb-entry
x_refsource_OSVDB
21185
vdb-entry
x_refsource_OSVDB
15644
vdb-entry
x_refsource_BID
21191
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now