First published: Mon Mar 07 2005(Updated: )
SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.4 | |
phpMyFAQ | =1.4_alpha1 | |
phpMyFAQ | =1.5 | |
phpMyFAQ | =1.4_alpha2 | |
phpMyFAQ | =1.4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0702 is classified as a medium severity vulnerability due to the potential for SQL injection leading to unauthorized database modifications.
To fix CVE-2005-0702, upgrade phpMyFAQ to version 1.6 or later, which addresses this SQL injection issue.
CVE-2005-0702 affects phpMyFAQ versions 1.4, 1.4_alpha1, 1.4_alpha2, 1.4a, and 1.5.
Attackers can exploit CVE-2005-0702 to inject malicious SQL commands through the username field, allowing them to manipulate FAQ records in the database.
While CVE-2005-0702 is an older vulnerability, it remains a concern for any systems still running the affected versions of phpMyFAQ without necessary patches.