Vulnerabilities > CVE-2005-4218 - SQL Injection vulnerability in PHPwebthings 1.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpwebthings
nessus
exploit available

Summary

SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.

Vulnerable Configurations

Part Description Count
Application
Phpwebthings
1

Exploit-Db

descriptionPHPWebThings <= 1.4 (msg/forum) SQL Injection Exploit. CVE-2005-4218,CVE-2005-4226. Webapps exploit for php platform
fileexploits/php/webapps/1324.php
idEDB-ID:1324
last seen2016-01-31
modified2005-11-16
platformphp
port
published2005-11-16
reporterrgod
sourcehttps://www.exploit-db.com/download/1324/
titlePHPWebThings <= 1.4 msg/forum SQL Injection Exploit
typewebapps

Nessus

NASL familyCGI abuses
NASL idPHPWEBTHINGS_SQL_INJECTION.NASL
descriptionThe remote host is running the phpWebThings application framework. The version of phpWebThings installed on the remote host does not properly sanitize user input in the
last seen2020-06-01
modified2020-06-02
plugin id20170
published2005-11-08
reporterThis script is Copyright (C) 2005-2018 Ferdy Riphagen
sourcehttps://www.tenable.com/plugins/nessus/20170
titlephpWebThings Multiple Scripts SQL Injection