SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
History

Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Softbizscripts
Softbizscripts b2b Trading Marketplace Script
CPEs cpe:2.3:a:softbiz:b2b_trading_marketplace_script:*:*:*:*:*:*:*:* cpe:2.3:a:softbizscripts:b2b_trading_marketplace_script:*:*:*:*:*:*:*:*
Vendors & Products Softbiz
Softbiz b2b Trading Marketplace Script
Softbizscripts
Softbizscripts b2b Trading Marketplace Script

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-01T11:00:00.000Z

Updated: 2024-08-07T23:31:48.647Z

Reserved: 2005-12-01T00:00:00.000Z

Link: CVE-2005-3937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-12-01T06:03:00.000

Modified: 2026-04-06T14:41:30.440

Link: CVE-2005-3937

cve-icon Redhat

No data.