CVE-2005-3521: SQL Injection
SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) aname parameter or (2) user field of the login page.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3521?
CVE-2005-3521 is considered a high severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-3521?
To fix CVE-2005-3521, upgrade to a patched version of e107 CMS that addresses this SQL injection vulnerability.
Which versions of e107 CMS are affected by CVE-2005-3521?
CVE-2005-3521 affects e107 CMS versions from 0.617 to 0.6173, including specific versions like 0.6171 and 0.6172.
Can CVE-2005-3521 be exploited to gain unauthorized access?
Yes, CVE-2005-3521 can allow attackers to bypass authentication and inject HTML or script, facilitating unauthorized access.
What parameters are involved in the CVE-2005-3521 SQL injection vulnerability?
The SQL injection vulnerability in CVE-2005-3521 involves the 'a_name' parameter and the 'user' field of the login page.