CVE-2005-3937
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- softbizscripts/b2b trading marketplace script
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.htmlBroken Link
- http://secunia.com/advisories/17808Third Party Advisory
- http://www.osvdb.org/21252Broken Link
- http://www.osvdb.org/21253Broken Link
- http://www.osvdb.org/21254Broken Link
- http://www.osvdb.org/21255Broken Link
- http://www.securityfocus.com/bid/15652Broken Link
- http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.htmlBroken Link
- http://secunia.com/advisories/17808Third Party Advisory
- http://www.osvdb.org/21252Broken Link
- http://www.osvdb.org/21253Broken Link
- http://www.osvdb.org/21254Broken Link
- http://www.osvdb.org/21255Broken Link
- http://www.securityfocus.com/bid/15652Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.