First published: Fri Mar 04 2005(Updated: )
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
s0nic Paranews | =2.0.4b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-0646 is classified as critical due to its potential for remote SQL injection attacks.
To fix CVE-2005-0646, you should update to a later version of paNews that addresses the SQL injection vulnerability.
CVE-2005-0646 affects users of paNews version 2.0.4b who are using the vulnerable auth.php script.
CVE-2005-0646 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
Yes, there are known exploits for CVE-2005-0646 that demonstrate how to leverage the SQL injection vulnerability for attacking the application.