CVE-2005-3939
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- wsn knowledge base/wsn knowledge base
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2005/11/wsn-knowledge-base-sql-inj-vuln.html
- http://secunia.com/advisories/17810Vendor Advisory
- http://www.osvdb.org/21262
- http://www.osvdb.org/21263
- http://www.osvdb.org/21264
- http://www.securityfocus.com/bid/15656Exploit
- http://pridels0.blogspot.com/2005/11/wsn-knowledge-base-sql-inj-vuln.html
- http://secunia.com/advisories/17810Vendor Advisory
- http://www.osvdb.org/21262
- http://www.osvdb.org/21263
- http://www.osvdb.org/21264
- http://www.securityfocus.com/bid/15656Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.