← back
CVE-2005-2675

CVE-2005-2675

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.2%
from disclosure to weapon0 days
Published on NVDAug 23
1st PoCAug 20
exploitation probability
1.2%top 36% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter to list.php, (7) m parameter to journal.php, (8) x or (9) n parameter to forums.php, or (10) w parameter to links.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.