7.5
CVSSv2

CVE-2005-4218

Published: 14/12/2005 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote malicious users to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.

Vulnerable Product Search on Vulmon Subscribe to Product

phpwebthings phpwebthings 1.4

Exploits

#!/bin/bin/perl #-----------------------------------------------------# #- SQL injection in phpwebthing v 144 #- Founder by Qptan & Exploting by AhLam #- wwwleZeCom Only For Geek Hacker's #- coded by AhLaM A1M|at|hotmailcom #- wwwlezrcom/vb/showthreadphp?t=6557 #---------------------------------------- ...
<?php # ---phpwebth14_xplphp 1047 16/11/2005 # # # # PHPWebThings 14 "msg" and "forum" SQL injection / Administrative # # credentials disclosure and remote commands execution # # ...