CVE-2005-1384

critical

Description

Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/20308

http://www.vupen.com/english/advisories/2005/0423

http://securitytracker.com/id?1013834

http://pridels0.blogspot.com/2006/03/phpcoin-poc.html

http://marc.info/?l=bugtraq&m=111473522804665&w=2

Details

Source: Mitre, NVD

Published: 2005-05-03

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical