CVE-2005-3395: SQL Injection
Published Nov 1, 2005
·Updated
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
Affected Software
1 affected component
Invision Power Services Invision Gallery=2.0.3
Remediation
Patch Available
Event History
Nov 1, 2005
CVE Published
12:47 PM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3395?
CVE-2005-3395 is classified as a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2005-3395?
To fix CVE-2005-3395, upgrade Invision Gallery to a later version that addresses the SQL injection vulnerability.
3
What software is affected by CVE-2005-3395?
CVE-2005-3395 specifically affects Invision Gallery version 2.0.3.
4
Can CVE-2005-3395 lead to data breaches?
Yes, CVE-2005-3395 can potentially lead to data breaches if an attacker successfully exploits the SQL injection vulnerability.
5
What measures can I implement to mitigate CVE-2005-3395?
To mitigate CVE-2005-3395, validate and sanitize all user inputs to prevent SQL injection attacks.