Lucene search

K
cveMitreCVE-2005-4018
HistoryDec 05, 2005 - 11:03 a.m.

CVE-2005-4018

2005-12-0511:03:00
mitre
web.nvd.nist.gov
22
cve-2005-4018
sql injection
ls.php
landshop real estate commerce system
remote attackers
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.111

Percentile

95.2%

SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.

Affected configurations

Nvd
Node
landshopreal_estate_commerce_systemRange0.6.3
VendorProductVersionCPE
landshopreal_estate_commerce_system*cpe:2.3:a:landshop:real_estate_commerce_system:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.111

Percentile

95.2%

Related for CVE-2005-4018