CVE-2005-3937 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.3% (pctl 71)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.35% — more likely to be exploited than 71% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-12-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| softbizscripts | b2b trading marketplace script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SoftBiz B2B trading Marketplace Script - SQL Injection | 2009-12-25 |
| exploit-db | SoftBiz B2B trading Marketplace Script 1.1 - 'selloffers.php?cid' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz B2B trading Marketplace Script 1.1 - 'buyoffers.php?cid' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz B2B trading Marketplace Script 1.1 - 'products.php?cid' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz B2B trading Marketplace Script 1.1 - 'profiles.php?cid' SQL Injection | 2005-11-30 |
References
- http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html
- http://secunia.com/advisories/17808
- http://www.osvdb.org/21252
- http://www.osvdb.org/21253
- http://www.osvdb.org/21254
- http://www.osvdb.org/21255
- http://www.securityfocus.com/bid/15652
- http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html
- http://secunia.com/advisories/17808
- http://www.osvdb.org/21252
- http://www.osvdb.org/21253
- http://www.osvdb.org/21254
- http://www.osvdb.org/21255
- http://www.securityfocus.com/bid/15652
→ the Explorer · watch your stack · NVD