CVE

Id
15072  
CVE No.
CVE-2005-3868  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.  
Phase
Assigned (20051129)  
Votes
None (candidate not yet proposed)  
Comments