Vulnerabilities > CVE-2005-4140 - SQL Injection vulnerability in Website Baker 2.5.2/2.6

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
website-baker
nessus
exploit available

Summary

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.

Vulnerable Configurations

Part Description Count
Application
Website_Baker
2

Exploit-Db

descriptionWebsite Baker <= 2.6.0 Login Bypass / Remote Code Execution Exploit. CVE-2005-4140. Webapps exploit for php platform
idEDB-ID:1363
last seen2016-01-31
modified2005-12-08
published2005-12-08
reporterrgod
sourcehttps://www.exploit-db.com/download/1363/
titleWebsite Baker <= 2.6.0 Login Bypass / Remote Code Execution Exploit

Nessus

NASL familyCGI abuses
NASL idWEBSITEBAKER_ADMIN_LOGIN_SQL_INJECTION.NASL
descriptionThe remote host is running Website Baker, a PHP-based content management system. The installed version of Website Baker fails to validate user input to the username parameter of the
last seen2020-06-01
modified2020-06-02
plugin id20839
published2006-02-02
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/20839
titleWebsite Baker Admin Login SQL Injection