7.5
CVSSv2

CVE-2005-0841

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote malicious users to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfamily phpmyfamily 1.4

Exploits

# Tested with version 125 /str0ke Login as admin without pass: Login: "' OR 'a'='a' AND admin='Y'/*" (without quotes) Password: (empty) # milw0rmcom [2005-03-21] ...