CVE-2005-2398

Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:php_surveyor:php_surveyor:0.98:*:*:*:*:*:*:*

Information

Published : 2005-07-26 21:00

Updated : 2017-07-10 18:32


NVD link : CVE-2005-2398

Mitre link : CVE-2005-2398


JSON object : View

Advertisement

dedicated server usa

Products Affected

php_surveyor

  • php_surveyor