First published: Fri Sep 23 2005(Updated: )
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3046 is classified as a high severity vulnerability due to the potential for remote code execution and database manipulation.
To fix CVE-2005-3046, upgrade phpMyFAQ to version 1.5.2 or later, which addresses the SQL injection vulnerability.
The implications of CVE-2005-3046 include unauthorized access to administrator privileges and potential data breaches.
Users of phpMyFAQ version 1.5.1 are affected by CVE-2005-3046, specifically those not patched against this vulnerability.
Attackers can exploit CVE-2005-3046 to modify SQL queries through the user field, allowing for privilege escalation.