SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.
References
Configurations
History
21 Nov 2024, 00:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://forum.word-press.net/index.php?&showtopic=76&st=0&#entry181 - | |
References | () http://pridels0.blogspot.com/2005/11/phpwordpress-30-sql-inj.html - | |
References | () http://secunia.com/advisories/17733 - Vendor Advisory | |
References | () http://www.osvdb.org/21110 - | |
References | () http://www.securityfocus.com/bid/15582 - | |
References | () http://www.vupen.com/english/advisories/2005/2594 - |
Information
Published : 2005-11-26 22:03
Updated : 2024-11-21 00:02
NVD link : CVE-2005-3844
Mitre link : CVE-2005-3844
CVE.ORG link : CVE-2005-3844
JSON object : View
Products Affected
phpwordpress
- php_news_and_article_manager
CWE