Lucene search

K
cveMitreCVE-2005-2156
HistoryJul 06, 2005 - 4:00 a.m.

CVE-2005-2156

2005-07-0604:00:00
mitre
web.nvd.nist.gov
28
cve
2005
2156
sql injection
phpnews
vulnerability
news.php
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.002

Percentile

52.6%

SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

Affected configurations

Nvd
Node
phpnewsphpnewsMatch1.2.5
VendorProductVersionCPE
phpnewsphpnews1.2.5cpe:2.3:a:phpnews:phpnews:1.2.5:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.002

Percentile

52.6%

Related for CVE-2005-2156