CVE-2005-3423
Last modified
CVE-2005-3423 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Subdreamer | Subdreamer | 2.2.1 |
References
- http://rst.void.ru/papers/advisory35.txtVendor Advisory
- http://secunia.com/advisories/17378Vendor Advisory
- http://rst.void.ru/papers/advisory35.txtVendor Advisory
- http://secunia.com/advisories/17378Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3423?
How severe is CVE-2005-3423?
How do I fix CVE-2005-3423?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3417phpBB 2.0.17 and earlier, when the register_long_arrays dire…
- CVE-2005-3418Multiple cross-site scripting (XSS) vulnerabilities in phpBB…
- CVE-2005-3419SQL injection vulnerability in usercp_register.php in phpBB …
- CVE-2005-3420usercp_register.php in phpBB 2.0.17 allows remote attackers …
- CVE-2005-3421estcmd in Hyper Estraier 1.0.1 on Windows systems allows rem…
- CVE-2005-3422Cross-site scripting (XSS) vulnerability in error.asp in ASP…
- CVE-2005-3424Cross-site scripting (XSS) vulnerability in GNUMP3D before 2…
- CVE-2005-3425Cross-site scripting (XSS) vulnerability in GNUMP3D before 2…
- CVE-2005-3426Cisco CSS 11500 Content Services Switch (CSS) with SSL termi…
- CVE-2005-3427The Cisco Management Center (MC) for IPS Sensors (IPS MC) 2.…
- CVE-2005-3428Cross-site scripting (XSS) vulnerability in Rockliffe MailSi…
- CVE-2005-3429Rockliffe MailSite Express before 6.1.22, with the option to…
Are you affected by CVE-2005-3423?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
