VulnerabilityModified
CVE-2005-1082
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.
HIGH 7.5EPSS 1.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- azerbaijan development group/azdgdating
- Source
- cve@mitre.org
References
- http://www.osvdb.org/15525
- http://www.securityfocus.com/archive/1/395530Vendor Advisory
- http://www.securityfocus.com/archive/1/438607/100/100/threaded
- http://www.securityfocus.com/bid/13082Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20051
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27436
- http://www.osvdb.org/15525
- http://www.securityfocus.com/archive/1/395530Vendor Advisory
- http://www.securityfocus.com/archive/1/438607/100/100/threaded
- http://www.securityfocus.com/bid/13082Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20051
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27436
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.