Description
SQL injection vulnerability in process_signup.php in PHP Handicapper allows remote attackers to execute arbitrary SQL commands via the serviceid parameter. NOTE: on 20060210, the vendor disputed this issue, saying "this is 100% false reporting, this is a slander campaign from a customer who had a vulnerability in his SERVER not the software." However, followup investigation strongly suggests that the original report is correct
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:17:22.389Z
Reserved: 2005-11-03T00:00:00.000Z
Link: CVE-2005-3497
No data.
Status : Modified
Published: 2005-11-04T00:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2005-3497
No data.
OpenCVE Enrichment
No data.
Weaknesses