Vulnerabilities > CVE-2005-4218 - SQL Injection vulnerability in PHPwebthings 1.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | PHPWebThings <= 1.4 (msg/forum) SQL Injection Exploit. CVE-2005-4218,CVE-2005-4226. Webapps exploit for php platform |
file | exploits/php/webapps/1324.php |
id | EDB-ID:1324 |
last seen | 2016-01-31 |
modified | 2005-11-16 |
platform | php |
port | |
published | 2005-11-16 |
reporter | rgod |
source | https://www.exploit-db.com/download/1324/ |
title | PHPWebThings <= 1.4 msg/forum SQL Injection Exploit |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | PHPWEBTHINGS_SQL_INJECTION.NASL |
description | The remote host is running the phpWebThings application framework. The version of phpWebThings installed on the remote host does not properly sanitize user input in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20170 |
published | 2005-11-08 |
reporter | This script is Copyright (C) 2005-2018 Ferdy Riphagen |
source | https://www.tenable.com/plugins/nessus/20170 |
title | phpWebThings Multiple Scripts SQL Injection |