CVE-2005-4286

Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phplogcon:phplogcon:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:phplogcon:phplogcon:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:phplogcon:phplogcon:1.2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://cvs.sourceforge.net/viewcvs.py/phplogcon/phplogcon/submit.php?r1=1.4&r2=1.5 - () http://cvs.sourceforge.net/viewcvs.py/phplogcon/phplogcon/submit.php?r1=1.4&r2=1.5 -
References () http://secunia.com/advisories/18053 - Patch, Vendor Advisory () http://secunia.com/advisories/18053 - Patch, Vendor Advisory
References () http://www.phplogcon.com/Article9.phtml - () http://www.phplogcon.com/Article9.phtml -
References () http://www.vupen.com/english/advisories/2005/2930 - () http://www.vupen.com/english/advisories/2005/2930 -

Information

Published : 2005-12-16 11:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-4286

Mitre link : CVE-2005-4286

CVE.ORG link : CVE-2005-4286


JSON object : View

Products Affected

phplogcon

  • phplogcon