SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Softbiz Web_Hosting_Directory_Script
cpe:2.3:a:softbiz:web_hosting_directory_script:*:*:*:*:*:*:*:*
|
— | — |