CVE Database
/

CVE-2005-4226

Back to search

CVE-2005-4226

Published: Dec 14, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters in forum.php, (3) the msg and forum parameters in forum_edit.php, (4) the msg and forum parameters in forum_write.php, (5) the tekst parameter in guestbook.php, (6) the menuoption parameter in index.php, and the (7) sel_avatar parameter in myaccount.php. NOTE: the forum.php/forum vector is already identified by CVE-2005-3585.

VendorProductVersions

n/a

n/a

affected
n/a

References

21653
vdb-entry
x_refsource_OSVDB
21650
vdb-entry
x_refsource_OSVDB
ADV-2005-2860
vdb-entry
x_refsource_VUPEN
18011
third-party-advisory
x_refsource_SECUNIA
21654
vdb-entry
x_refsource_OSVDB
21651
vdb-entry
x_refsource_OSVDB
21656
vdb-entry
x_refsource_OSVDB
21655
vdb-entry
x_refsource_OSVDB
21652
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now