7.5
CVE-2005-3968
- EPSS 2.02%
- Veröffentlicht 03.12.2005 19:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.02% | 0.784 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://rgod.altervista.org/phpx_359_xpl.html
http://secunia.com/advisories/17858
http://securitytracker.com/id?1015300
http://www.osvdb.org/21384
http://www.phpx.org/news.php?news_id=139
http://www.securityfocus.com/archive/1/418253/100/0/threaded
http://www.securityfocus.com/bid/15680
http://www.vupen.com/english/advisories/2005/2696
https://exchange.xforce.ibmcloud.com/vulnerabilities/23459