CVE Vulnerabilities

CVE-2005-2000

Published: Jun 15, 2005 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.

Affected Software

Name Vendor Start Version End Version
Pafiledb Php_arena 1.1.3 (including) 1.1.3 (including)
Pafiledb Php_arena 2.1.1 (including) 2.1.1 (including)
Pafiledb Php_arena 3.0 (including) 3.0 (including)
Pafiledb Php_arena 3.0_beta_3.1 (including) 3.0_beta_3.1 (including)
Pafiledb Php_arena 3.1 (including) 3.1 (including)

References