CVE-2005-4792: SQL Injection
SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arbitrary SQL commands via the module parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4792?
CVE-2005-4792 is considered to be a high severity SQL injection vulnerability due to its potential for remote command execution.
How do I fix CVE-2005-4792?
To fix CVE-2005-4792, upgrade to phpWebSite version 0.10.2 or later, which resolves the SQL injection vulnerability.
What systems are affected by CVE-2005-4792?
CVE-2005-4792 affects phpWebSite version 0.10.1 and earlier, along with specific older versions listed in the CPE entries.
Can CVE-2005-4792 lead to data loss?
Yes, CVE-2005-4792 can lead to data loss as attackers can execute arbitrary SQL commands, potentially altering or deleting database records.
Is CVE-2005-4792 commonly exploited?
CVE-2005-4792 has been a target for attackers, which makes it vital for affected users to apply security updates promptly.