Unrated severityNVD Advisory· Published Nov 30, 2005· Updated Apr 16, 2026
CVE-2005-3914
CVE-2005-3914
Description
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
Affected products
1- cpe:2.3:a:affcommerce:affcommerce:1.1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/17690nvdExploitVendor Advisory
- www.osvdb.org/21070nvdExploitVendor Advisory
- www.osvdb.org/21071nvdExploitVendor Advisory
- www.osvdb.org/21072nvdExploitVendor Advisory
- www.securityfocus.com/bid/15545nvdExploitVendor Advisory
- pridels0.blogspot.com/2005/11/affcommerce-multiple-sql-inj.htmlnvd
- www.vupen.com/english/advisories/2005/2550nvd
News mentions
0No linked articles in our index yet.