First published: Tue Oct 25 2005(Updated: )
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections file, and (5) the dl_id parameter in the Download file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nuked-klan Partenaires Module | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3305 is considered a critical SQL injection vulnerability that can allow attackers to execute arbitrary SQL commands.
To fix CVE-2005-3305, it is recommended to update Nuked Klan to a version that addresses these SQL injection vulnerabilities.
CVE-2005-3305 affects several components, including the Forum, Links, Sections, and Downloads files in Nuked Klan 1.7.
Attackers can exploit CVE-2005-3305 to perform unauthorized SQL commands, leading to data manipulation or unauthorized access to the database.
Yes, there are known public exploits for CVE-2005-3305 that demonstrate how attackers can manipulate the vulnerable parameters.