CVE-2005-0702
Published Mar 7, 2005
Last updated 16 years ago
Overview
- Description
- SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89D2E1DC-EA41-4819-B700-78546932755C" }, { "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:1.4_alpha1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0B69808-C3F4-401E-996D-88091203698E" }, { "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:1.4_alpha2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39CA9672-6651-4654-89AB-AF45A3EB2492" }, { "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:1.4a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E47EB76A-2314-4978-A146-C6C73CF018C2" }, { "criteria": "cpe:2.3:a:phpmyfaq:phpmyfaq:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BCB304A-9B0D-4C9F-80FA-5BEDB9753A45" } ], "operator": "OR" } ] } ]