First published: Sat Dec 17 2005(Updated: )
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Almondsoft Affiliate Network Classifieds | =5.02 | |
Almondsoft Affiliate Network Classifieds | =5.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-4312 is considered high due to the ability for remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-4312, you should validate and sanitize user input for the id parameter in the index.php file.
AlmondSoft Almond Classifieds version 5.02 is vulnerable to CVE-2005-4312.
Yes, CVE-2005-4312 can potentially lead to data loss or compromise as it allows arbitrary SQL command execution.
A temporary workaround for CVE-2005-4312 includes restricting access to the index.php file until a patch can be applied.