CVE-2005-3968
N/A
N/A
Summary
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.vupen.com/english/advisories/2005/2696
- http://www.securityfocus.com/bid/15680
- http://rgod.altervista.org/phpx_359_xpl.html
- http://securitytracker.com/id?1015300
- http://www.phpx.org/news.php?news_id=139
- http://www.osvdb.org/21384
- http://www.securityfocus.com/archive/1/418253/100/0/threaded
- http://secunia.com/advisories/17858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23459
References
- http://www.vupen.com/english/advisories/2005/2696
- http://www.securityfocus.com/bid/15680
- http://rgod.altervista.org/phpx_359_xpl.html
- http://securitytracker.com/id?1015300
- http://www.phpx.org/news.php?news_id=139
- http://www.osvdb.org/21384
- http://www.securityfocus.com/archive/1/418253/100/0/threaded
- http://secunia.com/advisories/17858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23459
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.