CVE-2005-3840
Last modified
CVE-2005-3840 is a vulnerability of currently unknown severity. SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Omnistar Interactive | Omnistar Live | <= 5.2 |
References
- http://secunia.com/advisories/17697Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2561Vendor Advisory
- http://secunia.com/advisories/17697Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2561Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3840?
How severe is CVE-2005-3840?
How do I fix CVE-2005-3840?
Are you affected by CVE-2005-3840?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
